CVE-2026-14499

HIGH

IBM Langflow OSS 1.0.0-1.10.1 - Python Interpreter Command Injection

Title source: manual
STIX 2.1

Description

IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input in the Python Interpreter component.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory patch
https://www.ibm.com/support/pages/node/7279996

Scores

CVSS v3 8.8
EPSS 0.0045
EPSS Percentile 36.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (2)
IBM/Langflow OSS 1.0.0 - 1.10.1
langflow/langflow 1.0.0 - 1.10.2
Published Jul 17, 2026
Tracked Since Jul 18, 2026