CyberRota Analysis
AI-GeneratedIBM Langflow OSS versions 1.0.0 to 1.10.3 are vulnerable to arbitrary code execution due to insufficient restrictions on pathnames, allowing remote authenticated attackers to exploit this flaw. Organizations utilizing these versions should prioritize patching to mitigate the risk of unauthorized access and potential system compromise. Immediate action is recommended for users in environments where sensitive data or critical operations are involved.
CVE
CVE-2026-84889
Severity
HIGH
CVSS
8.8
EPSS
0.53%
Original NVD Description
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.