HIGHVulnerability
Verified
Global
CISA KEV: IBM Langflow — IBM Langflow Code Injection Vulnerability
·Source: CISA KEV
Updated:
Executive Summary
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
Analysis
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. Added to CISA Known Exploited Vulnerabilities catalog on 2026-08-04. Remediation due: 2026-08-07.