Skip to content
HighVulnerability

CVE-2026-88962: IBM Langflow OSS code execution via improper control of code generation

Identifier
CVE-2026-88962
Published
Record updated
View JSON
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.8%

Summary

IBM Langflow OSS versions 1.0.0 through 1.12.2 are affected by CVE-2026-88962. A remote attacker with valid authentication can execute arbitrary code because the product improperly controls code generation.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.