CVE-2026-10561: fallo crítico en IBM Langflow OSS
Unauthenticated Remote Code Execution in Langflow OSS PythonREPLComponent via Builtins Injection
Publicada el · Actualizada el
28Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 10epss 0.8%
probabilidad de explotación
0.8%top 44% de las CVE
explotación observada
noninguna fuente lo reporta
IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Productos afectados
IBM · Langflow OSSCVEs relacionadas — IBM Langflow OSS
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-9198CRITICALUnauthenticated Remote Code Execution via Auto-Login Bypass and Code ValidationEPSS 28.7%KEVCVE-2026-9103CRITICALUnauthenticated Superuser Token Issuance via Auto-Login EndpointEPSS 3.2%CVE-2026-19295CRITICALLangflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcementEPSS 3.0%CVE-2026-18729HIGHLangflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcementEPSS 1.8%CVE-2026-8476CRITICALDisk Cache Deserialization Remote Code Execution VulnerabilityEPSS 1.0%CVE-2026-12940CRITICALLangflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpointsEPSS 0.9%