IBM disclosed five high-severity vulnerabilities in Langflow OSS affecting versions 1.0.0 through 1.10.0, including multiple paths to remote code execution, privilege escalation, and arbitrary file write. The issues are tracked as CVE-2026-9135, CVE-2026-8476, CVE-2026-8481, CVE-2026-8635, and CVE-2026-8859. Reported weaknesses include code injection through unvalidated dynamic CodeInput fields in the Policies component, unsafe pickle.loads() deserialization in the disk cache, direct execution of user-supplied Python in the /api/v1/validate/code endpoint, database manipulation that can elevate an authenticated user to superuser, and path traversal in the APIRequest component's Save to File feature via crafted Content-Disposition filenames.
Several of the flaws require only authenticated access and can lead to arbitrary Python or system command execution with the privileges of the Langflow server process, creating a path to full host compromise in some deployments. IBM released Langflow OSS 1.10.1 to address all five vulnerabilities and advised organizations to upgrade immediately; additional mitigation guidance includes reviewing file-system permissions and sanitizing or removing cached data where possible. Public reporting said no active exploitation had been confirmed at publication time.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
A later reference reports that IBM released Langflow OSS version 1.10.1 to remediate all five disclosed vulnerabilities. The same source says no active exploitation had been confirmed at the time of publication.
Five vulnerabilities affecting Langflow OSS versions 1.0.0 through 1.10.0 were published, covering code injection, unsafe deserialization, code execution via a validation endpoint, privilege escalation, and path traversal. The disclosed CVEs are CVE-2026-9135, CVE-2026-8476, CVE-2026-8481, CVE-2026-8635, and CVE-2026-8859.
The CVE record for CVE-2026-8635 says IBM PSIRT received the vulnerability on 2026-07-17. The flaw affects Langflow OSS 1.0.0 through 1.10.0 and can enable privilege escalation to superuser and arbitrary command execution.
The CVE record for CVE-2026-8481 states that IBM PSIRT received the vulnerability on 2026-07-17. The issue affects Langflow OSS 1.0.0 through 1.10.0 and allows authenticated users to execute arbitrary Python code through the code validation endpoint.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
threataft.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.