CVE-2026-9196: IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic As
highvulnerabilityLLM-Specific
security
Summary
IBM Langflow OSS (an open-source tool for building AI applications) versions 1.0.0 through 1.10.3 has a vulnerability where an authenticated attacker can execute unintended code because the application runs Python code generated by the AI model during validation before a user approves it. This allows attackers to perform harmful actions like accessing the network, interacting with files, or stealing data using the permissions of the Langflow backend process.
Vulnerability Details
CVSS Score
8.1(high)
EPSS (30-day exploit probability)
EPSS: 0.2%
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
network
Attack Complexity
low
Privileges Required
low
User Interaction
none
Disclosure Date
August 5, 2026
Classification
Attack SophisticationModerate
Impact (CIA+S)
integrityconfidentialityavailability
Affected Vendors
Monthly digest — independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-9196
First tracked: August 6, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 92%