CVE-2026-10561

critical

Description

IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise

References

https://www.ibm.com/support/pages/node/7277242

https://github.com/langflow-ai/langflow/security/advisories/GHSA-8qpj-27x8-pwpq

https://github.com/langflow-ai/langflow/releases/tag/v1.10.1

https://github.com/langflow-ai/langflow/pull/13700

https://github.com/langflow-ai/langflow/commit/2754c84aad1306f463db1c3bbb3e8ffbe85da77d

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38245

Details

Source: Mitre, NVD

Published: 2026-06-22

Updated: 2026-06-26

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 10

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.0082