Advisories
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
67 items
CVE-2026-13446 affects IBM Langflow OSS versions 1.0.0 through 1.10.1. The flaw is hard-coded credentials, such as a password or cryptographic key, used for inbound authentication, outbound communication to external components, or encryption of internal data. Classified as CWE-798 (Use of Hard-coded Credentials), the entry was published by NVD on 07/17/2026, and NVD has not yet provided an assessment.
IBM Langflow OSS versions 1.0.0 through 1.10.0 contain a path traversal flaw in the APIRequest component. When the "Save to File" feature is enabled, filenames taken from HTTP response Content-Disposition headers are joined to the temporary directory path without sanitization. An attacker controlling an external HTTP server can supply filenames containing ../ sequences, allowing arbitrary file writes to locations the Langflow process can access.
CVE-2026-8635 affects IBM Langflow OSS versions 1.0.0 through 1.10.0. An authenticated user can escalate privileges to superuser by directly manipulating the database. From there the attacker can execute arbitrary system commands and achieve full system compromise with Langflow service permissions. The weakness is classified as CWE-94, Improper Control of Generation of Code ('Code Injection').
IBM Langflow OSS versions 1.0.0 through 1.10.0 contain a flaw in the webhook authentication logic that skips API key validation when WEBHOOK_AUTH_ENABLE is set to False, which is the default. A remote attacker who knows a flow's UUID can execute that flow as if they were its owner, potentially leading to Remote Code Execution (RCE). The NVD assessment has not yet been provided.
CVE-2026-8481 affects IBM Langflow OSS versions 1.0.0 through 1.10.0. The POST /api/v1/validate/code endpoint accepts user-supplied Python code and runs it directly with exec(), without sandboxing, input validation, or privilege restrictions. Any authenticated user can therefore execute arbitrary system commands with the full privileges of the Langflow server process.
IBM Langflow OSS versions 1.0.0 through 1.10.0 contain a critical remote code execution flaw tracked as CVE-2026-8476. The AsyncDiskCache class calls Python's unsafe pickle.loads() on cached objects read from disk, with no validation, integrity check or authentication. An attacker who can influence cached data, through file system access, malicious workflow inputs, custom components or API manipulation, can execute arbitrary code and fully compromise the system with the privileges of the Langflow server process.
IBM Langflow OSS versions 1.0.0 through 1.10.0, including Langflow up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d), contain a code injection flaw in the Policies component's ToolGuard integration that bypasses the allow_custom_components=false control. Validation checks only node_template["code"]["value"], not the dynamic CodeInput fields that store generated ToolGuard Python files, so malicious Python persisted in Flow.data runs server-side when a guarded tool is invoked. Authenticated users with flow creation privileges can gain arbitrary Python execution, and the agentic MCP update_flow_component_field tool, which accepts attacker-controlled user_id parameters, enables cross-tenant injection into other users' flows.
IBM Langflow OSS versions 1.0.0 through 1.10.0 contain CVE-2026-9103, an improper authentication flaw in the /api/v1/login/auto_login endpoint. When AUTO_LOGIN is enabled, which is the default, the endpoint issues long-lived superuser bearer tokens without requiring authentication, which may let an unauthenticated network attacker gain full administrative access. Permissive CORS settings may also expose tokens to unintended origins.
CVE-2026-9202 affects IBM Langflow OSS 1.0.0 through 1.10.0 and is classified as CWE-306, Missing Authentication for Critical Function. Unauthenticated attackers can create unlimited user accounts on any Langflow instance. When NEW_USER_IS_ACTIVE=true, which the source describes as a documented deployment option, those accounts are immediately active and can authenticate to reach RCE endpoints without needing AUTO_LOGIN.
CVE-2026-9198 affects IBM Langflow OSS versions 1.0.0 through 1.10.0. An unauthenticated attacker can chain /api/v1/auto_login, which mints SUPERUSER tokens to any network caller, with /api/v1/validate/code, which executes user code via exec(), to achieve full RCE on default Langflow deployments. The weakness is classified as CWE-94, Improper Control of Generation of Code ('Code Injection').
CVE-2026-9810 affects the AI Copilot WordPress plugin before 1.5.4. The plugin does not bind OAuth access tokens to a WordPress user and accepts any valid token as an administrator session. Unauthenticated attackers who complete the public OAuth flow can run privileged MCP tools as an administrator, including arbitrary user creation and role escalation.
CVE-2026-30623 affects LiteLLM 1.18.10 in its MCP server creation functionality. Users can add MCP servers through a JSON configuration that sets arbitrary command and args values, which LiteLLM executes on the host without validation, allowing an attacker to run arbitrary operating system commands. Successful exploitation may result in remote code execution with the privileges of the LiteLLM process.
In multi-tenant HTTP deployments of n8n-mcp (ENABLE_MULTI_TENANT=true), the locally stored workflow version history was not isolated per tenant. An authenticated tenant could read other tenants' workflow version snapshots, which can include node credential references and authorization headers, and could delete their backups. Affected versions are <= 2.56.0; stdio and single-tenant HTTP deployments are not affected.
Fix: Fixed in 2.56.1, which isolates the stored version history per instance; upgrading runs a one-time migration that isolates existing history and clears previously stored, un-scoped backups. Workarounds: set DISABLED_TOOLS=n8n_workflow_versions in the server environment, run each tenant on a separate instance with its own database, or restrict network access to the HTTP endpoint to trusted operators.
CVE-2026-48561 is an improper neutralization of special elements used in a command, classified as CWE-77 (command injection), in Microsoft Copilot. The source states that an unauthorized attacker can execute code over a network. NVD has not yet provided an assessment, and the record was published on 07/14/2026.
CVE-2026-12484 affects keras-team/keras version 3.15.0. The public keras.layers.TorchModuleWrapper.from_config method calls torch.load(..., weights_only=False) without requiring an explicit unsafe opt-in, so it deserializes attacker-controlled PyTorch pickle data by default when no SafeModeScope(True) context is active. Processing untrusted Keras layer configurations this way can lead to arbitrary code execution.
IBM Langflow OSS versions 1.0.0 through 1.10.1 contain a flaw in the SaveToFile component. An authenticated attacker can supply absolute paths to victim storage locations, reading and modifying other users' uploaded files and breaking the storage ownership boundary between users. In append mode the attacker can read victim contents and copy them into their own namespace, and in overwrite mode they can replace victim file contents.
CVE-2026-8056 affects IBM Langflow OSS versions 1.0.0 through 1.10.0. Authenticated users can override component parameters at runtime through the API, due to a flaw in the parameter filtering mechanism within the apply_tweaks() function. The weakness is classified as CWE-94, Improper Control of Generation of Code ('Code Injection').
CVE-2026-7872 affects IBM Langflow OSS versions 1.0.0 through 1.10.0. An authenticated attacker can read arbitrary files, including the JWT signing key, and use that key to forge authentication tokens for any user. The weakness is classified as CWE-22, Improper Limitation of a Pathname to a Restricted Directory.
CVE-2026-7755 affects IBM Langflow OSS versions 1.0.0 through 1.10.0. The flaw is incomplete validation enforcement on MCP server configuration files, which could allow remote code execution. NIST has not yet provided an NVD assessment.
CVE-2026-7754 affects IBM Langflow OSS 1.0.0 through 1.10.0 and Langflow 1.9.0. The flaw allows server-side request forgery (SSRF) because of an insecure default configuration and incomplete enforcement of the SSRF protection mechanism. NVD has not yet provided an assessment, and the record was published 07/17/2026.