A critical vulnerability tracked as CVE-2026-9198 allows unauthenticated remote code execution against default-configured Langflow OSS deployments by chaining two exposed API behaviors. According to IBM's security bulletin, the /api/v1/auto_login endpoint can issue SUPERUSER bearer tokens to any network caller, and the /api/v1/validate/code endpoint then executes attacker-controlled Python through exec(). IBM said the validator can trigger execution through Python decorators, default arguments, and annotations at function definition time, giving attackers arbitrary command execution on the host. The issue affects Langflow OSS versions 1.0.0 through 1.10.0, carries a CVSS 3.1 score of 9.8, and has no listed workaround.
A draft Metasploit Framework pull request adds an exploit module for the flaw and says successful exploitation can yield a Meterpreter session on vulnerable systems. The module author reported testing against Langflow 1.8.4 on Ubuntu 22.04, describing the attack as unauthenticated and effective on default deployments. The pull request also links the bug to CISA KEV, underscoring active operational relevance, while IBM advises organizations to upgrade to Langflow OSS 1.10.1 to remediate the exposure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-08-04, a GitHub automation bot added Rapid7 Metasploit pull request #21753 to the Metasploit Kanban project and moved it to Todo. The pull request was the draft exploit module for CVE-2026-9198.
IBM, acting as the CNA, published the CVE record for CVE-2026-9198, formally documenting the critical Langflow OSS remote code execution flaw affecting versions 1.0.0 through 1.10.0. The record described the exploit chain involving /api/v1/auto_login and /api/v1/validate/code and assigned the issue a CVSS 9.8 severity rating.
On 2026-07-02, IBM published a security bulletin for CVE-2026-9198, describing an unauthenticated remote code execution flaw in default-configured Langflow OSS deployments. The bulletin said the issue chains the /api/v1/auto_login endpoint with /api/v1/validate/code and recommended upgrading to Langflow OSS 1.10.1.
A draft pull request in Rapid7's Metasploit Framework proposed a new exploit module for CVE-2026-9198, stating the chain can yield full unauthenticated RCE against default Langflow deployments and was tested against Langflow 1.8.4 on Ubuntu 22.04. The PR also noted that successful exploitation results in a Meterpreter session.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcecve.org
Open sourceibm.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.