Langflow Flaw Exposes Default Deployments to Remote Code Execution
A critical vulnerability in IBM-owned Langflow has been discovered to allow unauthenticated attackers to execute code remotely on default deployments.
The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-9198 to its Known Exploited Vulnerabilities catalog after identifying evidence of active exploitation, urging organizations to apply the vendor's mitigation guidance as soon as possible.
Langflow is a low-code AI builder that allows users to construct agent workflows without needing to know much about the underlying code. The vulnerability affects Langflow OSS versions 1.0.0 through 1.10.0 and can be mitigated by upgrading to version 1.10.1 or later.
The flaw, which combines two issues that allow an unauthenticated attacker to execute code remotely, has already been exploited according to the CISA.