CVE-2026-10134
Critical · CVSS 10.0IBM Langflow OSS — Server-Side Code Injection (CWE-94) via tool_code manipulation enabling RCE, SSRF, secret exfiltration, and persistence
- CVSS
- 10.0
- nvd
- EPSS
- 0.31%
- 23th pct
- KEV
- No
- Class
- other
- CWE-94
Description
IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversation, message, file upload, and saved component in the Langflow database, can connect to internal services, abuse cloud metadata endpoints, laterally move to other tenants on the same Langflow instance, and Establish persistence by modifying the public flow's `tool_code` so normal `/api/v1/build/...` calls by any user re-execute attacker code at each build.
Search profile — drives PoC discovery
Symbols tool_code/api/v1/build/flowtool_code injectionbuild endpointcloud metadatasaved componentpublic flow
Keywords CVE-2026-10134IBM Langflow OSSLangflow tool_code injectionLangflow RCELangflow code injectionLangflow SSRFLangflow secret exfiltrationLangflow persistenceLangflow /api/v1/build exploitLangflow 1.9.3 vulnerabilityCWE-94 Langflow
Versions: 1.0.0 through 1.9.3
References
Status: enriched · ingested 2026-07-02T18:00:43.000Z · profiled 2026-07-02T18:30:43.000Z