CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-7803

Critical · CVSS 9.8

IBM Langflow OSS — Arbitrary Code Execution via improper validation of flow nodes

CVSS
9.8
nvd
EPSS
KEV
No
Class
other
CWE-20, NVD-CWE-noinfo

Description

IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validation of flow nodes with missing or empty component type fields.

Search profile — drives PoC discovery

Symbols flow nodescomponent typenode validationempty component typemissing component typeflow executionLangflow APICustomComponentbuild_configcomponent_type
Keywords CVE-2026-7803IBM Langflow OSSLangflow arbitrary code executionLangflow flow node validationLangflow missing component typeLangflow empty component type RCELangflow 1.0.0 1.10.0 exploitLangflow improper validation PoCLangflow CWE-20 RCE
Versions: 1.0.0 through 1.10.0

References

Status: enriched · ingested 2026-07-03T00:00:43.000Z · profiled 2026-07-03T00:30:43.000Z