nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-17624 CVE-2026-17624
HIGH
Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
Record summary
CVE-2026-17624 has a selected CVSS score of 8.5 (high).
Description
IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of module imports.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 5, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Langflow OSSBrowse IBM / Langflow OSS | CVE List | 1.0.0 to ≤ 1.10.3 | affected |
References
2ibm.comVendor advisorypatch
https://www.ibm.com/support/pages/node/7282646