NPM · JULY 2026 · CONFIRMED

Critical IBM Langflow OSS Vulnerability: Remote Code Execution Risk

CVE-2026-12946Severity: CRITICAL

A critical vulnerability has been confirmed in IBM Langflow OSS versions 1.0.0 through 1.10.0, enabling remote code execution due to improper input validation. Users of these versions are at risk.

What happened

The vulnerability, tracked as CVE-2026-12946 with a CVSS score of 9.9, allows a remote attacker to inject arbitrary code on the system. This is due to insufficient control of user input code in the affected versions. The National Vulnerability Database (NVD) reports that the improper handling of environment variables in the MCP stdio launcher is the root cause.

CISA has warned that hackers are actively exploiting this vulnerability alongside others in Langflow, N-central, and Apache Tomcat. It is crucial for users to assess their exposure and take immediate action.

To mitigate the risk, avoid using affected versions of IBM Langflow until a patch is available. Monitor for updates from IBM and apply them as soon as they are released. For detailed information, consult the primary sources listed in the threat data.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If ibm langflow is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats