SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-79742

HIGH · CVSS 8.8 EPSS 0.54%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

IBM Langflow OSS versions 1.0.0 to 1.11.5 are vulnerable to remote code execution due to an inadequate environment variable blocklist, which could be exploited by authenticated attackers. Organizations using these versions should prioritize patching to mitigate the risk of unauthorized code execution and potential system compromise. Immediate action is recommended for users managing sensitive data or critical infrastructure.

CVE
CVE-2026-79742
Severity
HIGH
CVSS
8.8
EPSS
0.54%

Original NVD Description

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist.