Critical Vulnerability in IBM Langflow OSS: Remote Code Execution Risk
IBM Langflow OSS versions 1.0.0 through 1.10.1 are confirmed to have a critical vulnerability allowing unauthenticated remote code execution via environment variable injection.
What happened
The vulnerability, tracked as CVE-2026-12940 with a CVSS score of 9.8, exists in the MCP stdio launcher due to a missing blocklist for certain environment variables. This flaw enables attackers to execute arbitrary code on affected systems. Additionally, CVE-2026-12946 and CVE-2026-13435, both with CVSS scores of 9.9, indicate further critical vulnerabilities in input validation and code injection within the same version range. Users are advised to upgrade to a version beyond 1.10.1 once available and review environment variables in affected deployments. For detailed information, consult the NVD entries for CVE-2026-12940, CVE-2026-12946, and CVE-2026-13435.
How 0Day mitigates this
ibm langflow is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.