NPM · SEPTEMBER 2026 · CONFIRMED

Critical Vulnerability in IBM Langflow OSS: CVE-2026-85025

Severity
CRITICAL
CVSS
9.8
Affected component
ibm langflow (npm)
Patched version
Not yet available
CVE-2026-85025

IBM Langflow OSS versions 1.0.0 through 1.11.5 have a critical vulnerability that could allow unauthenticated attackers to execute arbitrary code and access or modify chat sessions.

What happened

IBM Langflow OSS versions 1.0.0 through 1.11.5 contain a critical vulnerability tracked as CVE-2026-85025. This vulnerability arises from improper enforcement of security restrictions on publicly shared endpoints. An unauthenticated attacker could exploit this to execute arbitrary code and access or modify chat sessions. The vulnerability was first flagged on 2026-09-10T21:17:51.990000+00:00 and confirmed shortly after on 2026-09-10T23:12:12.284276+00:00. To assess your exposure, check if your deployment includes any of the affected versions of the ibm langflow npm package.

The CVSS score for this vulnerability is 9.8, indicating a critical severity level. Multiple independent sources have confirmed the vulnerability, including NVD entries for CVE-2026-12944, CVE-2026-79724, CVE-2026-81204, and CVE-2026-85025. These sources collectively underscore the severity and potential impact of this flaw.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If ibm langflow is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if you are using ibm langflow npm package versions 1.0.0 through 1.11.5.

What should I do right now?

Upgrade to a version beyond 1.11.5 or apply any available patches immediately.

Has this vulnerability been exploited in the wild?

No, there is no evidence that this vulnerability has been exploited in the wild.

Where can I find more information about this vulnerability?

Consult the primary sources listed in the incident data for detailed information.

Sources

Join the 0Day waitlist →

← Back to all threats