10
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Description
IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise
AI Analysis
Unauthenticated remote code execution vulnerability in Langflow OSS PythonREPLComponent via builtins injection
Basic Information
ID
CVE-2026-10561
Source
ibm
Published
Jun 22, 2026 at 13:22
Affected Product
Vendor
IBM
Product
Langflow OSS
Version
1.0.0
Affected Versions
IBM Langflow OSS 1.0.0
CWE Classification
AI Assessment
AI Score
10 / 10
AI Severity
Critical
Vendor
IBM
Product
Langflow OSS
Version
1.0.0-1.9.3