CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-10561

Critical · CVSS 10.0

IBM Langflow OSS — Authentication bypass leading to arbitrary Python code execution (RCE)

CVSS
10.0
nvd
EPSS
KEV
No
Class
other
CWE-94

Description

IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise

Search profile — drives PoC discovery

Symbols langflowPython executionauthentication bypasscode injectionflow executioncustom componentevalexecrun_codeexecute_codesandbox escape
Keywords CVE-2026-10561IBM Langflow OSSLangflow RCELangflow authentication bypassLangflow code executionLangflow unauthenticated RCELangflow 1.9.3 exploitLangflow PoCCWE-94 LangflowLangflow Python sandbox escape
Versions: 1.0.0 through 1.9.3

References

Status: enriched · ingested 2026-06-27T00:00:38.000Z · profiled 2026-06-30T18:30:14.000Z