Skip to content
HighVulnerability

CVE-2026-93447: IBM Langflow OSS unsafe deserialization of cache values from Redis

Identifier
CVE-2026-93447
Published
Record updated
View JSON
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.4%

Summary

IBM Langflow OSS versions 1.0.0 through 1.12.2 are affected by CVE-2026-93447. An attacker who holds the server secret and has Redis write access can submit a malicious serialized cache value. When that value is retrieved, deserialization could execute attacker-controlled code with the privileges of the service process.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.