{"data":{"id":"7c3d5741-ec52-409b-a28d-4e2742534c76","title":"CVE-2026-97674: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary OS commands due…","summary":"IBM Langflow OSS versions 1.0.0 through 1.12.2 contain a flaw that allows a remote, authenticated attacker to execute arbitrary OS commands. The flaw stems from improper neutralization of special elements used in an OS command, classified as 'Code Injection' and described as improper control of code generation.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-97674","publishedAt":"2026-10-07T01:16:36.247Z","cveId":"CVE-2026-97674","cweIds":["CWE-94"],"cvssScore":"8.1","cvssSeverity":"high","severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedPackageNames":null,"affectedVendors":[],"affectedVendorsRaw":["IBM Langflow OSS"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.003,"epssCheckedAt":"2026-10-10T06:42:00.270Z","kevDateAdded":null,"advisoryAliases":["GHSA-x724-4ccj-hq65"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":"2026-10-10T03:42:37.834Z","patchAvailable":null,"disclosureDate":"2026-10-07T01:16:36.247Z","capecIds":["CAPEC-242"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":["AML.T0010"]}}