NPM · JULY 2026 · CONFIRMED

IBM Langflow OSS 1.0.0 to 1.10.0 Remote Code Execution Vulnerability

CVE-2026-9198Severity: CRITICAL

IBM Langflow OSS versions 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability that allows unauthenticated attackers to achieve full remote code execution on default deployments.

What happened

IBM Langflow OSS versions 1.0.0 through 1.10.0 have been confirmed to contain a critical remote code execution vulnerability tracked as CVE-2026-9198. This vulnerability allows unauthenticated attackers to execute arbitrary code on affected systems. The vulnerability exists in the disk-based caching mechanism where the AsyncDiskCache class uses Python's unsafe pickle.loads() function without validation, enabling arbitrary code execution when malicious pickle payloads are processed. Attackers with influence over cached data can achieve complete system compromise.

The severity of this vulnerability is rated as CRITICAL with a CVSS score of 9.8. The National Vulnerability Database (NVD) and the Dutch National Cyber Security Centre (NCSC) have published advisories (CVE-2026-9198 and NCSC-2026-0251) detailing the vulnerability and recommending immediate action.

To mitigate this threat, users are advised to upgrade to a version beyond 1.10.0 and review any affected deployments for unauthorized access. For more detailed information, consult the primary sources listed in the advisories.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If ibm langflow is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats