CVE-2026-14499

IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input in the Python Interpreter component.
References
Link Resource
https://www.ibm.com/support/pages/node/7279996 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-17 20:17

Updated : 2026-07-23 05:16


NVD link : CVE-2026-14499

Mitre link : CVE-2026-14499

CVE.ORG link : CVE-2026-14499


JSON object : View

Products Affected

langflow

  • langflow

linux

  • linux_kernel

microsoft

  • windows

apple

  • macos
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')