CVE-2026-14499

IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input in the Python Interpreter component.
References
Link Resource
https://www.ibm.com/support/pages/node/7279996 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

20 Jul 2026, 18:12

Type Values Removed Values Added
References () https://www.ibm.com/support/pages/node/7279996 - () https://www.ibm.com/support/pages/node/7279996 - Vendor Advisory
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
First Time Apple macos
Langflow langflow
Linux
Apple
Linux linux Kernel
Microsoft windows
Microsoft
Langflow

17 Jul 2026, 20:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-17 20:17

Updated : 2026-07-20 18:12


NVD link : CVE-2026-14499

Mitre link : CVE-2026-14499

CVE.ORG link : CVE-2026-14499


JSON object : View

Products Affected

langflow

  • langflow

microsoft

  • windows

apple

  • macos

linux

  • linux_kernel
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')