SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-81941

HIGH · CVSS 8.8 EPSS 0.80% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

IBM Langflow OSS versions 1.0.0 to 1.11.5 are vulnerable to arbitrary command execution by authenticated non-administrative users, who can exploit a misconfiguration in MCP Tools components. This vulnerability allows attackers to bypass critical server-side controls, potentially leading to sensitive data exposure, file system modifications, and lateral movement within the network. Organizations using affected versions should prioritize remediation to mitigate the risk of exploitation and protect their systems.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-81941
Severity
HIGH
CVSS
8.8
EPSS
0.80%

Original NVD Description

IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP Tools component configured to use a local stdio subprocess transport. This bypasses both the LANGFLOW_CUSTOM_COMPONENT_ADMIN_ONLY and LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS server-side controls intended to prevent exactly this class of access. Successful exploitation could lead to arbitrary command execution, sensitive data exposure (including credentials from the process environment), file system modification, and lateral movement to services reachable from the server.