CVE-2026-7871
Critical · CVSS 9.8IBM Langflow OSS — Insecure Deserialization RCE via Redis (CWE-502)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-502
Description
IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets, data, and system integrity.
Search profile — drives PoC discovery
Symbols RedisLangflowdeserializepicklecachearbitrary code executionapplication privileges
Keywords CVE-2026-7871IBM Langflow OSSLangflow Redis deserializationLangflow RCE RedisLangflow arbitrary code executionCWE-502 LangflowLangflow 1.0.0 1.10.0 exploitLangflow Redis cache RCE PoC
Versions: 1.0.0 through 1.10.0
References
Status: enriched · ingested 2026-07-03T00:00:43.000Z · profiled 2026-07-03T00:30:43.000Z