CVE-2026-9135 is a code injection vulnerability in IBM Langflow OSS affecting versions 1.0.0 through 1.10.0. The flaw is in the Policies component's ToolGuard integration and allows bypass of the allow_custom_components=false security control. The validation logic inspects only the primary component source stored in the main code field, but does not validate dynamic CodeInput fields used to store generated ToolGuard Python files. An attacker can place malicious Python code into these unvalidated dynamic fields, where it is persisted in flow data and later executed on the server when a guarded tool is invoked through the ToolGuard runtime. The issue therefore enables authenticated users with flow creation privileges to introduce arbitrary backend-executed Python despite restrictions intended to block custom component execution. The vulnerability can also be leveraged for cross-tenant flow manipulation through the agentic MCP update_flow_component_field capability, which accepts attacker-controlled user_id values and can be abused to inject malicious code into another user's flow.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical code injection vulnerability in Langflow OSS ToolGuard integration that allows authenticated attackers to place malicious Python code in unvalidated dynamic fields and achieve server-side code execution.
A code injection vulnerability in IBM Langflow OSS's Policies component ToolGuard integration that bypasses the allow_custom_components=false security control, allowing authenticated users with flow creation privileges to achieve arbitrary Python code execution on the backend. The issue stems from validation checking only main component source code while failing to validate dynamic CodeInput fields containing generated ToolGuard Python files.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.