NPM · SEPTEMBER 2026 · EARLY WARNING

IBM Langflow OSS Vulnerability: Critical Supply-Chain Threat

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
CRITICAL
CVSS
9.6 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Affected component
ibm langflow (npm)
Patched version
Not yet available
CVE-2026-12944

An early warning has been issued for a critical vulnerability in IBM Langflow OSS versions 1.0.0 through 1.10.0 which may allow attackers to execute arbitrary Python code with root privileges.

What happened

An early warning has been issued regarding a critical vulnerability in IBM Langflow OSS versions 1.0.0 through 1.10.0. This vulnerability, tracked as CVE-2026-12944, reportedly allows attackers to execute arbitrary Python code with root privileges on the Langflow server. This could enable AWS credential theft, file exfiltration, and lateral movement within the Docker network. The vulnerability is under investigation and no exploitation in the wild has been confirmed yet.

The vulnerability was first flagged on 2026-09-14T22:16:56.950000+00:00. The CVSS score is 9.6, indicating a critical severity level. The attack type is classified as a supply-chain attack. Users of affected versions are advised to take immediate action to assess their exposure and implement mitigations as recommended.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If ibm langflow is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if you are using IBM Langflow OSS versions 1.0.0 through 1.10.0.

What should I do right now?

Monitor the primary sources for updates on patched versions and official fixes. Review your environments for any signs of compromise if you are using affected versions. Upgrade to a version beyond 1.10.0 once it becomes available.

Is there an official fix available yet?

No official fix has been published yet. Monitor the sources for updates.

What is the severity of this vulnerability?

The severity is critical with a CVSS score of 9.6.

Sources

Join the 0Day waitlist →

← Back to all threats