CVE-2026-7803
Critical · CVSS 9.8IBM Langflow OSS — Arbitrary Code Execution via improper validation of flow nodes
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-20, NVD-CWE-noinfo
Description
IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validation of flow nodes with missing or empty component type fields.
Search profile — drives PoC discovery
Symbols flow nodescomponent typenode validationempty component typemissing component typeflow executionLangflow APICustomComponentbuild_configcomponent_type
Keywords CVE-2026-7803IBM Langflow OSSLangflow arbitrary code executionLangflow flow node validationLangflow missing component typeLangflow empty component type RCELangflow 1.0.0 1.10.0 exploitLangflow improper validation PoCLangflow CWE-20 RCE
Versions: 1.0.0 through 1.10.0
References
Status: enriched · ingested 2026-07-03T00:00:43.000Z · profiled 2026-07-03T00:30:43.000Z