CVE-2026-7871Disclosure(langflow / langflow)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets, data, and system integrity.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langflow

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-07-01); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
langflow

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-01: 1Mentions · 2026-07-09: 1Technical Details · 2026-07-09: 107-0107-09
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    Langflowに重大な脆弱性6件、IBMが発見-未認証RCEからAPIキーの越境流用まで広範囲に影響(CVE-2026-10134、CVE-2026-7803、CVE-2026-7871、CVE-2026-7873、CVE-2026-10140、CVE-2026-7663) https://rocket-boys.co.jp/security-measures-lab/langflow-unauthenticated-rce-cve-2026-10134/ #セキュリティ対策Lab #security #securitynews

    Post summary

    IBM discovered six Langflow vulnerabilities, including unauthenticated RCE and API key misuse, identified by CVE numbers, but the article does not provide exploit code, active exploitation evidence, or remediation details.

    00000158
    462 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    We have just added an important vulnerability affecting IBM Langflow OSS (CVE-2026-7871) https://vuldb.com/vuln/374915

    Post summary

    The message announces the identification of CVE-2026-7871 in IBM Langflow OSS and directs readers to a vulnerability database entry.

    00000124
    2.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applangflowlangflow---

Explore more