CVE-2026-10561: falha crítica em IBM Langflow OSS
Unauthenticated Remote Code Execution in Langflow OSS PythonREPLComponent via Builtins Injection
Publicada em · Atualizada em
28Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 10epss 0.8%
probabilidade de exploração
0.8%top 44% das CVEs
exploração observada
nãonenhuma fonte reporta
IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Produtos afetados
IBM · Langflow OSSCVEs relacionadas — IBM Langflow OSS
No mesmo produto, das mais perigosas para as menos.
CVE-2026-9198CRITICALUnauthenticated Remote Code Execution via Auto-Login Bypass and Code ValidationEPSS 28.7%KEVCVE-2026-9103CRITICALUnauthenticated Superuser Token Issuance via Auto-Login EndpointEPSS 3.2%CVE-2026-19295CRITICALLangflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcementEPSS 3.0%CVE-2026-18729HIGHLangflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcementEPSS 1.8%CVE-2026-8476CRITICALDisk Cache Deserialization Remote Code Execution VulnerabilityEPSS 1.0%CVE-2026-12940CRITICALLangflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpointsEPSS 0.9%