CVE-2026-10561
Critical · CVSS 10.0IBM Langflow OSS — Authentication bypass leading to arbitrary Python code execution (RCE)
- CVSS
- 10.0
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-94
Description
IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise
Search profile — drives PoC discovery
Symbols langflowPython executionauthentication bypasscode injectionflow executioncustom componentevalexecrun_codeexecute_codesandbox escape
Keywords CVE-2026-10561IBM Langflow OSSLangflow RCELangflow authentication bypassLangflow code executionLangflow unauthenticated RCELangflow 1.9.3 exploitLangflow PoCCWE-94 LangflowLangflow Python sandbox escape
Versions: 1.0.0 through 1.9.3
References
Status: enriched · ingested 2026-06-27T00:00:38.000Z · profiled 2026-06-30T18:30:14.000Z