CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0251 [1.00] [M/H] Vulnerabilities fixed in IBM Langflow OSS

unknownpublic exploitCVE-2026-7667CVE-2026-7754CVE-2026-7755CVE-2026-7872CVE-2026-8056CVE-2026-8476
IBM has fixed multiple vulnerabilities in IBM Langflow OSS versions 1.0.0 to 1.10.0. The vulnerabilities in IBM Langflow OSS include: - executing arbitrary file changes by authenticated users via specially crafted Content-Disposition headers - server-side request forgery (SSRF) due to insecure default configurations - remote code execution (RCE) due to insufficient validation of MCP server configuration files - authenticated users can read files, including the JWT signing key, allowing for the forgery of authentication tokens - a vulnerability in the apply_tweaks() function that allows parameter overriding via the API and unsafe deserialization in the AsyncDiskCache class that enables RCE - the POST /api/v1/validate/code endpoint executes user-provided Python code without sandboxing, which can grant full server control - the webhook authentication mechanisms can be bypassed if the WEBHOOK_AUTH_ENABLE parameter is set to False, allowing unauthenticated users to execute flows - there is also a privilege escalation possible to superuser by abusing Langflow service permissions - a path traversal vulnerability in the APIRequest component allows files to be written to unwanted locations - the /api/v1/login/auto_login endpoint can issue long-lived superuser tokens without authentication when the AUTO_LOGIN feature is enabled, further exacerbated by permissive CORS settings - the Policies component contains a code injection vulnerability in the ToolGuard integration, where authenticated users with flow creation rights can execute arbitrary Python code - unauthenticated attackers can obtain superuser tokens and thereby perform full remote code execution on default installations. They can also create an unlimited number of active user accounts if the NEW_USER_IS_ACTIVE parameter is set to true, allowing them to

CSIRTS triage

What
Multiple vulnerabilities allow for remote code execution, server-side request forgery, and unauthorized file access.
Who is affected
Users of IBM Langflow OSS versions 1.0.0 to 1.10.0 are affected.
Urgency
Remediation is high urgency due to the potential for severe exploitation and the presence of multiple vulnerabilities.
Action
Upgrade to the latest version of IBM Langflow OSS to mitigate these vulnerabilities.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Langflow OSS

Get an email when a new Langflow OSS advisory drops — max one per day, one-click unsubscribe.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-07-21
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0251

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-7667coverage & exploitation statusNVD · CVE.org
CVE-2026-7754coverage & exploitation statusNVD · CVE.org
CVE-2026-7755coverage & exploitation statusNVD · CVE.org
CVE-2026-7872coverage & exploitation statusNVD · CVE.org
CVE-2026-8056coverage & exploitation statusNVD · CVE.org
CVE-2026-8476coverage & exploitation statusNVD · CVE.org
CVE-2026-8481coverage & exploitation statusNVD · CVE.org
CVE-2026-8505coverage & exploitation statusNVD · CVE.org
CVE-2026-8635coverage & exploitation statusNVD · CVE.org
CVE-2026-8859coverage & exploitation statusNVD · CVE.org
CVE-2026-9103coverage & exploitation statusNVD · CVE.org
CVE-2026-9135coverage & exploitation statusNVD · CVE.org
CVE-2026-9198coverage & exploitation statusNVD · CVE.org
CVE-2026-9202coverage & exploitation statusNVD · CVE.org
CVE-2026-14499coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from NCSC-NL Advisories