{"data":{"id":"0533e072-def2-4ab0-944d-25b8125320fc","title":"CVE-2026-8635: IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipul","summary":"IBM Langflow OSS (open-source software) versions 1.0.0 through 1.10.0 has a vulnerability where authenticated users (those with login access) can escalate privileges to superuser (gain the highest level of system access) by directly manipulating the database, potentially executing arbitrary system commands (running any code they want) and compromising the entire system. This is caused by improper control of code generation (code injection, where attackers inject malicious code into the system).","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-8635","publishedAt":"2026-07-17T20:17:31.527Z","cveId":"CVE-2026-8635","cweIds":["CWE-94"],"cvssScore":"9.9","cvssSeverity":"critical","severity":"critical","attackType":[],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["IBM Langflow"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-07-17T20:17:31.527Z","capecIds":["CAPEC-242"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality","availability"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}