CVE-2026-17630
Received Received - Intake

Remote Code Execution in IBM Langflow OSS

Vulnerability report for CVE-2026-17630, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: IBM Corporation

Description

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper validation of configuration parameters.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ibm langflow_oss From 1.0.0 (inc) to 1.10.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-184 The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IBM Langflow OSS versions 1.0.0 through 1.10.3 have a vulnerability where improper validation of configuration parameters allows remote attackers to execute arbitrary code on affected systems.

Detection Guidance

Detecting this vulnerability requires checking for IBM Langflow OSS versions 1.0.0 through 1.10.3. Use commands like 'pip show langflow' or check version files in the installation directory. Inspect configuration parameters for improper validation, especially remote input handling.

Impact Analysis

This vulnerability could allow an attacker to take control of your system, steal data, install malware, or disrupt services by exploiting misconfigured parameters in IBM Langflow OSS.

Compliance Impact

The vulnerability allows remote attackers to execute arbitrary code due to improper validation of configuration parameters. This could lead to unauthorized access, data breaches, or manipulation of sensitive information, which may violate compliance requirements under standards like GDPR or HIPAA that mandate strict access controls and data protection measures.

Mitigation Strategies

Update IBM Langflow OSS to a version beyond 1.10.3 to address improper validation of configuration parameters. Restrict network access to Langflow instances and monitor for unusual activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-17630. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart