IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve full system compromise with Langflow service permissions.
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/7278925 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2026-07-17 20:17
Updated : 2026-07-23 05:16
NVD link : CVE-2026-8635
Mitre link : CVE-2026-8635
CVE.ORG link : CVE-2026-8635
JSON object : View
Products Affected
langflow
- langflow
linux
- linux_kernel
microsoft
- windows
apple
- macos
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
