Back to search

CVE-2026-12944

CRITICAL
9.6NVD

IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential theft via IMDSv1 SSRF with full IAM role permissions, (2) arbitrary file exfiltration from the container filesystem, and (3) lateral movement to internal services (PostgreSQL, Redis) within the Docker network. The scanner incorrectly returns "validated": true, providing a false security signal.

Share:

CVSS v3.1 Score

9.6
/ 10.0
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Information

Published
14 sept. 2026
Updated
14 sept. 2026
Status
Received
Source
psirt@us.ibm.com

Weaknesses (CWE)

CWE-918

Similar CVEs

Other vulnerabilities of type CWE-918

Loading…

Monitor your products

Get automatic alerts for every new CVE affecting your equipment.

Enable monitoring