{"data":{"id":"b76b1b2b-e89e-4acb-abc7-ea9805f8f86b","title":"CVE-2026-81940: IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to impro","summary":"IBM Langflow OSS (open-source software) versions 1.0.0 through 1.11.5 has a vulnerability where an authenticated attacker (someone with login access) can execute arbitrary code (run any commands they want) by exploiting improper handling of special characters in flow display names (the text labels users give to workflows).","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-81940","publishedAt":"2026-09-10T22:17:03.083Z","cveId":"CVE-2026-81940","cweIds":["CWE-94"],"cvssScore":"8.8","cvssSeverity":"high","severity":"high","attackType":[],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["IBM Langflow"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-10T22:17:03.083Z","capecIds":["CAPEC-242"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality","availability"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}