CVE-2026-7873
Critical · CVSS 9.9IBM Langflow OSS — Authenticated OS Command Injection / Arbitrary File Read (Code Injection, CWE-94)
- CVSS
- 9.9
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-94
Description
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive files including credentials, enabling complete system compromise and lateral movement.
Search profile — drives PoC discovery
Symbols langflowos.systemsubprocessexecevalrun_codecode_executionCustomComponentfile_readcredentialslateral_movement
Keywords CVE-2026-7873IBM Langflow OSSLangflow RCELangflow command injectionLangflow arbitrary code executionLangflow authenticated RCELangflow OS commandLangflow file readLangflow credential exposureLangflow 1.0.0 1.10.0 exploitLangflow PoC
Versions: 1.0.0 through 1.10.0
References
Status: enriched · ingested 2026-07-03T00:00:43.000Z · profiled 2026-07-03T00:30:43.000Z