CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-7871

Critical · CVSS 9.8

IBM Langflow OSS — Insecure Deserialization RCE via Redis (CWE-502)

CVSS
9.8
nvd
EPSS
KEV
No
Class
other
CWE-502

Description

IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets, data, and system integrity.

Search profile — drives PoC discovery

Symbols RedisLangflowdeserializepicklecachearbitrary code executionapplication privileges
Keywords CVE-2026-7871IBM Langflow OSSLangflow Redis deserializationLangflow RCE RedisLangflow arbitrary code executionCWE-502 LangflowLangflow 1.0.0 1.10.0 exploitLangflow Redis cache RCE PoC
Versions: 1.0.0 through 1.10.0

References

Status: enriched · ingested 2026-07-03T00:00:43.000Z · profiled 2026-07-03T00:30:43.000Z