IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve full system compromise with Langflow service permissions.
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/7278925 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
20 Jul 2026, 17:48
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Apple macos
Langflow langflow Linux Apple Linux linux Kernel Microsoft windows Microsoft Langflow |
|
| CPE | cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* |
|
| References | () https://www.ibm.com/support/pages/node/7278925 - Vendor Advisory |
17 Jul 2026, 20:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-17 20:17
Updated : 2026-07-21 03:16
NVD link : CVE-2026-8635
Mitre link : CVE-2026-8635
CVE.ORG link : CVE-2026-8635
JSON object : View
Products Affected
langflow
- langflow
microsoft
- windows
apple
- macos
linux
- linux_kernel
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
