Advisory · CVE-2026-104334
Unauthenticated remote code execution in Langflow code generation
Langflow OSS releases 1.0.0 through 1.12.2 let a remote, unauthenticated attacker execute arbitrary code through an improperly constrained code generation path. IBM rates it critical at CVSS 9.8.
- Vendor
- IBM
- Product
- Langflow OSS
- Identifier / CWE
- CVE-2026-104334
CWE-94 - Action timing
- Immediate
Explain it like I’m five
Langflow is a robot workshop where people snap together AI building blocks. This flaw lets a total stranger walk into the workshop and tell the robot to build and run whatever machine they want, on the workshop's own power.
- 01Network reach
A remote attacker reaches the Langflow server over the network without any credentials.
- 02Payload into code generation
The attacker submits input that flows into Langflow's code generation path.
- 03Missing constraint
Langflow fails to properly control what the code generation path is allowed to produce.
- 04Arbitrary code runs
Attacker-controlled code executes with the privileges of the Langflow service process.
What happened
IBM disclosed CVE-2026-104334 on October 7, 2026: an improper control of code generation in IBM Langflow OSS versions 1.0.0 through 1.12.2. IBM scores it critical at CVSS 3.1 9.8, and exploitation needs no authentication and no user interaction.
Langflow is a widely used visual builder for AI applications and frequently runs on servers reachable over the network, including demo and individually managed instances. The flaw lets a remote attacker push input into the product’s code generation path and break out of its constraints, resulting in arbitrary code execution with the privileges of the service process.
IBM’s bulletin lists no workarounds or mitigations for these Langflow flaws; it recommends addressing them by upgrading.
What to do
- Inventory every Langflow deployment, including self-hosted, demo, research, and individually managed cloud instances, and confirm the running version.
- Upgrade affected instances (1.0.0 through 1.12.2) to the fixed release named in the IBM bulletin.
- Until patched, restrict network access to Langflow, keep it off the public internet, and require authentication everywhere.
- Review application and system logs for unusual flow execution, code execution calls, and unexpected outbound connections or processes.
- If exploitation cannot be excluded, rotate credentials held by or reachable from the Langflow host and review downstream systems.
Management note
This is the worst class of application flaw: unauthenticated, remote, and yielding full code execution on a platform teams often deploy casually. Langflow instances have a history of appearing on the public internet, so treat exposure assessment and patching as one task and assume internet-facing instances were reachable before the fix.