CVE-2026-7873

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
30/06/2026
Last modified:
02/07/2026

Description

IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive files including credentials, enabling complete system compromise and lateral movement.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* 1.0.0 (including) 1.10.0 (including)


References to Advisories, Solutions, and Tools