Critical Code Injection Vulnerability in IBM Langflow OSS
A critical code injection vulnerability has been confirmed in IBM Langflow OSS versions up to 1.9.2, enabling attackers to execute arbitrary Python code on the backend.
What happened
IBM Langflow OSS versions 1.0.0 through 1.10.0 contain a critical code injection vulnerability in the Policies component's ToolGuard integration (CVE-2026-9135). Attackers can embed malicious code in unvalidated dynamic fields to execute arbitrary Python code on the backend. This vulnerability has been confirmed by multiple independent sources, including the NCSC and NIST's NVD.
The vulnerability allows for remote code execution, enabling complete system compromise with the privileges of the Langflow server process. Attackers can influence cached data through file system access, malicious workflow inputs, custom components, or API manipulation.
To mitigate this threat, upgrade to a version beyond 1.10.0 where the vulnerability is fixed. Additionally, review and sanitize dynamically generated ToolGuard Python files to ensure no malicious code is present. Consult the primary sources for more detailed information and remediation steps.
How 0Day mitigates this
langflow is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.