CVE 10 CRITICAL

Unauthenticated Remote Code Execution in Langflow OSS PythonREPLComponent via Builtins Injection_CVE-2026-10561

10 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Description

IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise

AI Analysis

Unauthenticated remote code execution vulnerability in Langflow OSS PythonREPLComponent via builtins injection

Basic Information

ID CVE-2026-10561
Source ibm
Published Jun 22, 2026 at 13:22

Affected Product

Vendor IBM
Product Langflow OSS
Version 1.0.0
Affected Versions IBM Langflow OSS 1.0.0

CWE Classification

AI Assessment

AI Score 10 / 10
AI Severity Critical
Vendor IBM
Product Langflow OSS
Version 1.0.0-1.9.3

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.