HighVulnerability
CVE-2026-93675: IBM Langflow OSS remote code execution through dependency confusion
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-93675
- Published
- Record updated
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.8%
Summary
IBM Langflow OSS versions 1.0.0 through 1.12.2 are affected by CVE-2026-93675. A remote attacker could execute arbitrary code through an expected dependency confusion flaw.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- InfoStepSecurity Now Inventories AI Agent Skills in Your GitHub Repositories and on Developer Machines Similar attack · StepSecurity Blog
- LowCVE-2026-107288: Pydantic AI web fetch bypasses blocked_domains via hostname variantsSimilar attack · NVD/CVE Database
- LowOAuth grants pile up faster than you can review them. Here's how to keep up.Similar attack · BleepingComputer
- MediumTop MCP security resources — October 2026Similar attack · Adversa AI Blog
- MediumTensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing AttackSimilar attack · Socket Blog