IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments
https://www.vulncheck.com/blog/pwning-the-ai-stack
https://thehackernews.com/2026/08/cisa-flags-langflow-rce-tomcat-and-n.html
https://github.com/joaovicdev/EXPLOIT-CVE-2026-9198
https://github.com/chessalekin/cve-2026-9198_exploit
https://github.com/CuteeCat/CVE-2026-9198
https://github.com/Procjevt/CVE-2026-9198
https://github.com/samael0x4/CVE-2026-9198
https://github.com/0xgh057r3c0n/CVE-2026-9198
https://github.com/0xdak/CVE-2026-9198_exploit
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-9198