Act nowDisclosed

Advisory · CVE-2026-104334

Unauthenticated remote code execution in Langflow code generation

Langflow OSS releases 1.0.0 through 1.12.2 let a remote, unauthenticated attacker execute arbitrary code through an improperly constrained code generation path. IBM rates it critical at CVSS 9.8.

Vendor
IBM
Product
Langflow OSS
Identifier / CWE
CVE-2026-104334
CWE-94
Action timing
Immediate
ELI5

Explain it like I’m five

Langflow is a robot workshop where people snap together AI building blocks. This flaw lets a total stranger walk into the workshop and tell the robot to build and run whatever machine they want, on the workshop's own power.

SIMPLIFIED_ATTACK_PATH04 STEPS
  1. 01Network reach

    A remote attacker reaches the Langflow server over the network without any credentials.

  2. 02Payload into code generation

    The attacker submits input that flows into Langflow's code generation path.

  3. 03Missing constraint

    Langflow fails to properly control what the code generation path is allowed to produce.

  4. 04Arbitrary code runs

    Attacker-controlled code executes with the privileges of the Langflow service process.

What happened

IBM disclosed CVE-2026-104334 on October 7, 2026: an improper control of code generation in IBM Langflow OSS versions 1.0.0 through 1.12.2. IBM scores it critical at CVSS 3.1 9.8, and exploitation needs no authentication and no user interaction.

Langflow is a widely used visual builder for AI applications and frequently runs on servers reachable over the network, including demo and individually managed instances. The flaw lets a remote attacker push input into the product’s code generation path and break out of its constraints, resulting in arbitrary code execution with the privileges of the service process.

IBM’s bulletin lists no workarounds or mitigations for these Langflow flaws; it recommends addressing them by upgrading.

What to do

  1. Inventory every Langflow deployment, including self-hosted, demo, research, and individually managed cloud instances, and confirm the running version.
  2. Upgrade affected instances (1.0.0 through 1.12.2) to the fixed release named in the IBM bulletin.
  3. Until patched, restrict network access to Langflow, keep it off the public internet, and require authentication everywhere.
  4. Review application and system logs for unusual flow execution, code execution calls, and unexpected outbound connections or processes.
  5. If exploitation cannot be excluded, rotate credentials held by or reachable from the Langflow host and review downstream systems.

Management note

This is the worst class of application flaw: unauthenticated, remote, and yielding full code execution on a platform teams often deploy casually. Langflow instances have a history of appearing on the public internet, so treat exposure assessment and patching as one task and assume internet-facing instances were reachable before the fix.