CVE-2026-78569: IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomple
Summary
IBM Langflow OSS (an open-source AI tool) versions 1.0.0 through 1.11.5 has a security flaw where someone with login credentials can run malicious code on the system because the security scanner has an incomplete denylist (a list of blocked or dangerous items that isn't thorough enough).
Vulnerability Details
8.8(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
network
low
low
none
September 10, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-78569
First tracked: September 10, 2026 at 08:08 PM
Classified by LLM (prompt v3) · confidence: 92%