SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-14499

HIGH · CVSS 8.8 EPSS 0.45%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

IBM Langflow OSS versions 1.0.0 to 1.10.1 are vulnerable to a command injection flaw that allows authenticated users to execute arbitrary commands with elevated privileges due to inadequate input validation in the Python Interpreter component. This vulnerability poses a significant risk as it can lead to unauthorized access and control over the system. Organizations using affected versions should prioritize remediation to mitigate potential exploitation.

CVE
CVE-2026-14499
Severity
HIGH
CVSS
8.8
EPSS
0.45%

Original NVD Description

IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input in the Python Interpreter component.

Related CVEs

Other vulnerabilities affecting the same vendor(s)