NPM · JULY 2026 · CONFIRMED

Critical Vulnerability in IBM Langflow OSS: Remote Code Execution Risk

CVE-2026-12940Severity: CRITICAL

IBM Langflow OSS versions 1.0.0 through 1.10.1 are confirmed to have a critical vulnerability allowing unauthenticated remote code execution via environment variable injection.

What happened

The vulnerability, tracked as CVE-2026-12940 with a CVSS score of 9.8, exists in the MCP stdio launcher due to a missing blocklist for certain environment variables. This flaw enables attackers to execute arbitrary code on affected systems. Additionally, CVE-2026-12946 and CVE-2026-13435, both with CVSS scores of 9.9, indicate further critical vulnerabilities in input validation and code injection within the same version range. Users are advised to upgrade to a version beyond 1.10.1 once available and review environment variables in affected deployments. For detailed information, consult the NVD entries for CVE-2026-12940, CVE-2026-12946, and CVE-2026-13435.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If ibm langflow is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats