NPM · JULY 2026 · CONFIRMED

Critical Code Injection Vulnerability in IBM Langflow OSS

CVE-2026-9135Severity: CRITICAL

A critical code injection vulnerability has been confirmed in IBM Langflow OSS versions up to 1.9.2, enabling attackers to execute arbitrary Python code on the backend.

What happened

IBM Langflow OSS versions 1.0.0 through 1.10.0 contain a critical code injection vulnerability in the Policies component's ToolGuard integration (CVE-2026-9135). Attackers can embed malicious code in unvalidated dynamic fields to execute arbitrary Python code on the backend. This vulnerability has been confirmed by multiple independent sources, including the NCSC and NIST's NVD.

The vulnerability allows for remote code execution, enabling complete system compromise with the privileges of the Langflow server process. Attackers can influence cached data through file system access, malicious workflow inputs, custom components, or API manipulation.

To mitigate this threat, upgrade to a version beyond 1.10.0 where the vulnerability is fixed. Additionally, review and sanitize dynamically generated ToolGuard Python files to ensure no malicious code is present. Consult the primary sources for more detailed information and remediation steps.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If langflow is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats