critical · 9.9Automated intelligenceCVE-2026-12946

langflow-ai / Langflow

CVE-2026-12946: Langflow

IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.

software-vulnerability

Record details

Identifiers
CVE-2026-12946, psirt@us.ibm.com

Severity

CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Authority
psirt@us.ibm.com

Sources