SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-84889

HIGH · CVSS 8.8 EPSS 0.53%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

IBM Langflow OSS versions 1.0.0 to 1.10.3 are vulnerable to arbitrary code execution due to insufficient restrictions on pathnames, allowing remote authenticated attackers to exploit this flaw. Organizations utilizing these versions should prioritize patching to mitigate the risk of unauthorized access and potential system compromise. Immediate action is recommended for users in environments where sensitive data or critical operations are involved.

CVE
CVE-2026-84889
Severity
HIGH
CVSS
8.8
EPSS
0.53%

Original NVD Description

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.