CVE-2026-81941
Received Received - Intake

IBM Langflow OSS Command Injection Vulnerability

Vulnerability report for CVE-2026-81941, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-10

Assigner: IBM Corporation

Description

IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP Tools component configured to use a local stdio subprocess transport. This bypasses both the LANGFLOW_CUSTOM_COMPONENT_ADMIN_ONLY and LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS server-side controls intended to prevent exactly this class of access. Successful exploitation could lead to arbitrary command execution, sensitive data exposure (including credentials from the process environment), file system modification, and lateral movement to services reachable from the server.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-10
Generated
2026-09-11
AI Q&A
2026-09-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ibm langflow From 1.0.0 (inc) to 1.11.5 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user to execute arbitrary operating system commands on the server at the application's privilege level. It occurs by creating a flow with an MCP Tools component configured to use a local stdio subprocess transport, bypassing server-side controls like LANGFLOW_CUSTOM_COMPONENT_ADMIN_ONLY and LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS designed to prevent such access.

Detection Guidance

Detecting this vulnerability requires checking for IBM Langflow OSS versions 1.0.0 through 1.11.5 and verifying if MCP Tools components are configured with local stdio subprocess transport. Inspect server logs for unusual command execution patterns or unauthorized access attempts. No specific commands are provided in the context.

Impact Analysis

An attacker could gain control over the server, execute malicious commands, access sensitive data including credentials, modify files, and move laterally to other services connected to the server. This could lead to data breaches, system compromise, or further network infiltration.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Organizations may face compliance violations, legal penalties, and reputational damage due to potential data exposure and unauthorized system access.

Mitigation Strategies

Immediately upgrade IBM Langflow OSS to a version beyond 1.11.5. Disable or restrict non-administrative user access to MCP Tools components. Enable and enforce LANGFLOW_CUSTOM_COMPONENT_ADMIN_ONLY and LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS server-side controls. Monitor for suspicious activity and isolate affected systems if exploitation is suspected.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81941. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart