CVE-2026-9135Patch(apple / langflow)

LOWCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch apple langflow systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard integration that bypasses the allow_custom_components=false security control. The vulnerability exists because the validation mechanism only checks the main component source code in node_template["code"]["value"] but fails to validate dynamic CodeInput fields that store generated ToolGuard Python files. Attackers can embed malicious Python code in these unvalidated dynamic fields, which are persisted in Flow.data and later executed server-side when a guarded tool is invoked through the ToolGuard runtime. This allows authenticated users with flow creation privileges to achieve arbitrary Python code execution on the backend despite custom component restrictions. The vulnerability can be escalated through cross-tenant flow manipulation via the agentic MCP update_flow_component_field tool, which accepts attacker-controlled user_id parameters, enabling attackers to inject malicious code into victim users' flows. When combined with publicly accessible flows and specific misconfigurations (AUTO_LOGIN=true, NEW_USER_IS_ACTIVE=true), the attack can be conducted with reduced authentication requirements.

3.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langflow
  • linux_kernel
  • macos
  • windows

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-07-20)
  • 6 total mentions across 5 days

Affected systems

Products
langflowlinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-04-26: 1Mentions · 2026-07-17: 1Mentions · 2026-07-18: 1Mentions · 2026-07-19: 1Mentions · 2026-07-20: 2PoC Mentioned / Linked · 2026-07-20: 1Patch / Workaround · 2026-04-26: 1Patch / Workaround · 2026-07-17: 1Patch / Workaround · 2026-07-18: 1Patch / Workaround · 2026-07-19: 1Technical Details · 2026-07-17: 1Technical Details · 2026-07-18: 1Technical Details · 2026-07-19: 1Technical Details · 2026-07-20: 104-2607-1707-1807-1907-20
Signal classification4 categories
Patch
233.3%
Disclosure
233.3%
General
116.7%
PoC
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-261
Patch1
2026-07-171
Patch1
2026-07-181
Disclosure1
2026-07-191
Disclosure1
2026-07-202
General1PoC1
Full discourse6 posts
  • Jλckλι@J4ck3LSyN
    PoC

    Plausible CVE-2026-9135 PoC coming soon > IBM LangFlow Code Injection #CyberSecurity #InfoSec https://t.co/JwgJyhkqyt

    Post summary

    A proof‑of‑concept for CVE‑2026‑9135, which exploits code injection in IBM LangFlow, is expected soon; no exploit tools, active malware, or patches are discussed.

    13020191
    438 followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🚨 Critical Langflow OSS Alert 5 vulnerabilities (4× CVSS 9.9, 1× CVSS 7.8) affect Langflow OSS 1.0.0–1.10.0, enabling RCE, privilege escalation & arbitrary file writes. 🔧 Upgrade to Langflow OSS 1.10.1 immediately. 🔗 https://threataft.com/articles/langflow-oss-critical-rce-vulnerabilities-cve-2026-9135-cve-2026-8476-cve-2026-8481-cve-2026-8635-cve-2026-8859?utm_source=twitter&utm_medium=social&utm_campaign=share #CyberSecurity #Langflow #AI #RCE https://t.co/LO5DM9Ctur

    Post summary

    The tweet alerts on five critical vulnerabilities in Langflow OSS, highlighting RCE and privilege escalation, and urges users to upgrade to version 1.10.1 for remediation.

    1001020
    34 followersView on X
  • Jλckλι@J4ck3LSyN
    General

    Forgot to source: > https://www.ibm.com/support/pages/node/7278920 > https://www.thehackerwire.com/vulnerability/CVE-2026-9135/ > https://nvd.nist.gov/vuln/detail/CVE-2026-9135

    Post summary

    The provided text consists only of URL references with no explicit details about the CVE, so no definitive claims about PoC, exploitation, patches, or technical specifics can be made.

    0001026
    391 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - Langflow ToolGuard Policies code injection bypass (CVE-2026-9135) IBM Langflow OSS is vulnerable to server-side code injection in the Policies component’s ToolGuard integration, allowing attackers to bypass allow_custom_components=false. The root cause is improper input validation: validation checks only the primary component source, but does not validate dynamic CodeInput fields that persist generated ToolGuard Python files. An authenticated attacker with flow creation privileges can inject malicious Python into these CodeInput fields so it’s stored and later executed when a guarded tool runs, and some deployments may allow cross-tenant abuse by supplying attacker-controlled user_id values via update_flow_component_field. Successful exploitation results in arbitrary backend code execution, with potential tenant-to-tenant compromise, data theft, and full service takeover. 👉 Affected: IBM Langflow OSS 1.0.0–1.10.0 | No fix yet - treat as suspicious

    Post summary

    The post announces a critical server‑side code injection flaw in IBM Langflow OSS (CVE‑2026‑9135), detailing how authenticated attackers can inject arbitrary Python via CodeInput fields, but provides no PoC or evidence of active exploitation and notes that no patch is available yet.

    00010103
    254 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-9135 — CVSS 9.9/10 ██████████ IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d)... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/yyMDD5ybqH

    Post summary

    CVE-2026-9135 targets IBM Langflow OSS with a critical severity, and a patch has already been issued.

    10000136
    68 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    The CVE-2026-9135 patch is out, but what about the next one? If you rely on vendors to tell you when you're hacked, you're already too late. Learn to build your own Linux binary instrumentation tools. Read more-> https://tinyurl.com/yc2rs4rd #RockyLinux https://t.co/rMgg4cdHh8

    Post summary

    The tweet announces that the CVE‑2026‑9135 patch has been released and urges users to develop their own Linux binary instrumentation tools instead of relying on vendor alerts.

    1000064
    1.5K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Applangflowlangflow---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more