CVE-2026-7873
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
30/06/2026
Last modified:
02/07/2026
Description
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive files including credentials, enabling complete system compromise and lateral movement.
Impact
Base Score 3.x
9.90
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* | 1.0.0 (including) | 1.10.0 (including) |
To consult the complete list of CPE names with products and versions, see this page



