OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-97674

HIGH · CVSS 8.1 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-10-07 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

IBM Langflow OSS versions 1.0.0 to 1.12.2 are vulnerable to code injection, allowing remote authenticated attackers to execute arbitrary operating system commands. This flaw poses a significant risk as it can lead to unauthorized access and control over the affected systems. Organizations using these versions should prioritize patching to mitigate potential exploitation.

CVE
CVE-2026-97674
Severity
HIGH
CVSS
8.1
EPSS
0.30%

Original NVD Description

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command ('Code Injection'), aka improper control of code generation.

Related CVEs

Other vulnerabilities affecting the same vendor(s)