Langflow OSS vulnerability

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the MCP stdio server configuration.

Published 10 Sep 2026Updated 12 Sep 20261 sources
CVSS 8.8

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.