CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-10134

Critical · CVSS 10.0

IBM Langflow OSS — Server-Side Code Injection (CWE-94) via tool_code manipulation enabling RCE, SSRF, secret exfiltration, and persistence

CVSS
10.0
nvd
EPSS
0.31%
23th pct
KEV
No
Class
other
CWE-94

Description

IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversation, message, file upload, and saved component in the Langflow database, can connect to internal services, abuse cloud metadata endpoints, laterally move to other tenants on the same Langflow instance, and Establish persistence by modifying the public flow's `tool_code` so normal `/api/v1/build/...` calls by any user re-execute attacker code at each build.

Search profile — drives PoC discovery

Symbols tool_code/api/v1/build/flowtool_code injectionbuild endpointcloud metadatasaved componentpublic flow
Keywords CVE-2026-10134IBM Langflow OSSLangflow tool_code injectionLangflow RCELangflow code injectionLangflow SSRFLangflow secret exfiltrationLangflow persistenceLangflow /api/v1/build exploitLangflow 1.9.3 vulnerabilityCWE-94 Langflow
Versions: 1.0.0 through 1.9.3

References

Status: enriched · ingested 2026-07-02T18:00:43.000Z · profiled 2026-07-02T18:30:43.000Z