IBM disclosed CVE-2026-10561, a critical unauthenticated remote code execution flaw in Langflow OSS affecting versions 1.0.0 through 1.9.3. The vulnerability is rooted in improper isolation in the PythonREPLComponent: CPython's exec() restores full builtins access when the globals dictionary does not explicitly clear __builtins__, allowing attackers to bypass the intended import restrictions. IBM and downstream advisories rate the issue CVSS 3.1 10.0, noting it is remotely exploitable with low attack complexity, requires no privileges, and needs no user interaction.
The flaw can be chained with Langflow's default LANGFLOW_AUTO_LOGIN=true behavior, which exposes the /api/v1/auto_login endpoint and can issue a superuser JWT without credentials, enabling unauthenticated code execution on the host. Successful exploitation could lead to arbitrary OS command execution, theft of LLM provider keys, flow definitions and vector store credentials, and persistent compromise of affected systems. IBM recommends upgrading to Langflow OSS 1.9.4 immediately; no workaround was listed, and defenders are advised to apply vendor updates, harden access controls, and monitor for unauthorized activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
IBM published a security bulletin describing CVE-2026-10561, a critical unauthenticated remote code execution vulnerability affecting Langflow OSS versions 1.0.0 through 1.9.3. The bulletin says the flaw combines PythonREPLComponent builtins injection with Langflow's default auto-login behavior and recommends upgrading to version 1.9.4.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourceibm.com
Open sourcefirst.org
Open sourcefirst.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.