CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-7873

Critical · CVSS 9.9

IBM Langflow OSS — Authenticated OS Command Injection / Arbitrary File Read (Code Injection, CWE-94)

CVSS
9.9
nvd
EPSS
KEV
No
Class
other
CWE-94

Description

IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive files including credentials, enabling complete system compromise and lateral movement.

Search profile — drives PoC discovery

Symbols langflowos.systemsubprocessexecevalrun_codecode_executionCustomComponentfile_readcredentialslateral_movement
Keywords CVE-2026-7873IBM Langflow OSSLangflow RCELangflow command injectionLangflow arbitrary code executionLangflow authenticated RCELangflow OS commandLangflow file readLangflow credential exposureLangflow 1.0.0 1.10.0 exploitLangflow PoC
Versions: 1.0.0 through 1.10.0

References

Status: enriched · ingested 2026-07-03T00:00:43.000Z · profiled 2026-07-03T00:30:43.000Z