CVE-2026-10561Patch(langflow / langflow)

LOWCVSS 10.0 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch langflow langflow systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langflow

Threat summary

  • Patch or workaround signal is available
  • 11 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 10 signals
  • Disclosure: 5 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-07-16)
  • 11 total mentions across 5 days

Affected systems

Vendors
Products
langflow

Deep dive

Activity timeline11 mentions / 5d
01234Mentions · 2026-06-22: 3Mentions · 2026-06-23: 2Mentions · 2026-06-24: 1Mentions · 2026-06-25: 1Mentions · 2026-07-16: 4Patch / Workaround · 2026-06-22: 2Patch / Workaround · 2026-06-23: 1Patch / Workaround · 2026-06-24: 1Patch / Workaround · 2026-06-25: 1Patch / Workaround · 2026-07-16: 2Technical Details · 2026-06-22: 2Technical Details · 2026-06-23: 2Technical Details · 2026-06-24: 1Technical Details · 2026-06-25: 1Technical Details · 2026-07-16: 406-2206-2306-2406-2507-16
Signal classification2 categories
Patch
654.5%
Disclosure
545.5%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-06-223
Disclosure1Patch2
2026-06-232
Disclosure2
2026-06-241
Patch1
2026-06-251
Patch1
2026-07-164
Disclosure2Patch2
Full discourse11 posts
  • Daily CyberSecurity@the_yellow_fall
    Patch

    A critical Langflow RCE vulnerability (CVE-2026-10561) scores CVSS 10 and enables unauthenticated remote code execution. Upgrade to 1.9.4 now. #Langflow #RCE #CyberSecurity #CVE #PatchNow https://securityonline.info/langflow-rce-vulnerability https://t.co/OzM8MymtiJ

    Post summary

    The tweet announces CVE-2026-10561, a critical unauthenticated RCE in Langflow, and urges users to upgrade to version 1.9.4.

    000132687
    12.8K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-10561 — CVSS 10/10 ██████████ IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/vcsgJ9XZoL

    Post summary

    A critical vulnerability (CVE-2026-10561) in IBM Langflow OSS, rated CVSS 10/10, has been disclosed with an immediate patch available.

    11000231
    59 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Source: X search for vulnerability critical 2026 Posted: 2026-06-25T01:57:22.000Z Likes: 13 0day Intel: A critical Langflow RCE vulnerability (CVE-2026-10561) scores CVSS 10 and enable

    Post summary

    The post announces a critical remote code execution vulnerability (CVE-2026-10561) in Langflow with a CVSS score of 10, but does not provide PoC, exploit details, or mitigation information.

    1000049
    323 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    Full Tweet A critical Langflow RCE vulnerability (CVE-2026-10561) scores CVSS 10 and enables unauthenticated remote code execution. Upgrade to 1.9.4 now.

    Post summary

    The tweet announces CVE-2026-10561 as a critical RCE in Langflow with CVSS 10 and urges users to upgrade to version 1.9.4.

    1000043
    323 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    0day Intel: A critical Langflow RCE vulnerability (CVE-2026-10561) scores CVSS 10 and enable

    Post summary

    The tweet announces a 0day CVE-2026-10561, a critical Langflow RCE with CVSS 10, but provides no PoC, exploit code, or patch information.

    1000052
    323 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    CVE-2026-10561: A critical Langflow RCE vulnerability (CVE-2026-10561) scores CVSS 10 and enables unauthenticated remote code execution. Upgrade to 1.9.4 now. #Langflow #RCE #CyberSecurity #CVE #PatchNow (1.9.4)

    Post summary

    The post urges users to upgrade to Langflow 1.9.4 to fix CVE-2026-10561, a critical unauthenticated remote code execution flaw.

    1000055
    323 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    🐍 Unauthenticated RCE in IBM Langflow OSS (v1.0.0-1.9.3). CVE-2026-10561 scores a perfect CVSS 10: auth bypass + builtins injection via PythonREPLComponent = full system compromise, no creds needed. Patch now. #cybersecurity #infosec https://secalerts.co/vulnerability/CVE-2026-10561?utm_campaign=x https://t.co/FiP6trDQkO

    Post summary

    A critical unauthenticated RCE (CVE-2026-10561) in IBM Langflow OSS is disclosed, with a CVSS score of 10; a patch is immediately available.

    0000090
    842 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    #CVE-2026-10561 - Critical auth bypass in #IBM Langflow. Unauthenticated #RCE via #Python execution isolation flaw. #CVSS 10.0. No patch available—disconnect or mitigate immediately. #CVEAlert #infosec #sysadmin #devops #devsecops #developers more detailed info: https://www.valtersit.com/cve/CVE-2026-10561

    Post summary

    CVE‑2026‑10561 is a critical auth bypass in IBM Langflow that enables unauthenticated RCE via a Python isolation flaw; with no patch available, administrators should disconnect or mitigate immediately.

    0000092
    962 followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🚨 CRITICAL: IBM Langflow — CVSS 10.0 Unauthenticated RCE CVE-2026-10561 (CVSS 10.0) + CVE-2026-33017 (CVSS 9.3/10.0) Attacker sends one HTTP request → Python exec() → full system takeover. 🔗 https://threataft.com/articles/ibm-langflow-cve-2026-10561-unauthenticated-rce-ai-platform #CyberSecurity #ThreatIntel #infosec #AIsecurity

    Post summary

    The post announces two critical unauthenticated RCE vulnerabilities in IBM Langflow, detailing severity scores and a simple HTTP request exploitation vector, but offers no PoC, exploit code, or patch information.

    0000096
    31 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - IBM Langflow OSS Unauthenticated RCE (CVE-2026-10561) IBM Langflow OSS 1.0.0 through 1.9.3 suffers from improper isolation of Python execution combined with an authentication bypass. This allows an unauthenticated remote attacker to execute arbitrary code on the host system, resulting in full compromise. Severity: Critical (CVSS 10.0) 👉Affected: IBM Langflow OSS <= 1.9.3 Action: Upgrade to the latest patched version ץ

    Post summary

    IBM Langflow OSS <=1.9.3 is vulnerable to unauthenticated remote code execution due to improper Python isolation and an authentication bypass; users are urged to upgrade to a patched release.

    0000084
    226 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for IBM Langflow OSS (CVE-2026-10561) https://vuldb.com/vuln/372672

    Post summary

    A new IBM Langflow OSS vulnerability (CVE-2026-10561) with increased severity has been disclosed, with a link to its details but no additional technical or exploitation information.

    00000108
    2.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applangflowlangflow---

Explore more