CVE-2026-81941: IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating
Summary
IBM Langflow OSS versions 1.0.0 through 1.11.5 have a vulnerability where logged-in non-admin users can run arbitrary operating system commands (OS commands, or instructions executed directly on a computer) on the server by creating a flow that uses an MCP Tools component with local stdio subprocess transport, bypassing security controls meant to prevent this. This could allow attackers to access sensitive information, modify files, or move laterally (gain access to other connected systems) within the network.
Vulnerability Details
8.8(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
network
low
low
none
September 10, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
CVE-2024-27444: langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-81941
First tracked: September 10, 2026 at 08:08 PM
Classified by LLM (prompt v3) · confidence: 95%