CVE-2026-17625

HIGH

Langflow is affected by OS Command Injection in Model Context Protocol features

Title source: cna
STIX 2.1

Description

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory patch
https://www.ibm.com/support/pages/node/7282147

Scores

CVSS v3 7.2
EPSS 0.0078
EPSS Percentile 52.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (2)
IBM/Langflow OSS 1.0.0 - 1.10.3
langflow/langflow 1.0.0 - 1.11.0
Published Aug 05, 2026
Tracked Since Aug 05, 2026