{"data":{"id":"1e475092-7805-4de5-bdb8-a179ebb3b8b1","title":"CVE-2026-76059: IBM Langflow OSS 1.0.0 through 1.11.5 An attacker who could submit custom component source code could bypass the static ","summary":"IBM Langflow OSS (open-source software) versions 1.0.0 through 1.11.5 has a vulnerability where an attacker can upload malicious custom component code that tricks the static security scanner (a tool that checks code before it runs) by using alias tracking (following variable names to their actual values). Because of a logic error, the dangerous code is never checked against a blocklist of forbidden operations, allowing the attacker to execute arbitrary operating system commands on the server with the privileges of the running service.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-76059","publishedAt":"2026-09-10T22:16:59.590Z","cveId":"CVE-2026-76059","cweIds":["CWE-693"],"cvssScore":"8.8","cvssSeverity":"high","severity":"high","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["IBM Langflow","Langflow OSS"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-10T22:16:59.590Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","availability"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":["AML.T0010"]}}