CVE-2026-78569

Summary

IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete denylist in the security scanner.

Affected Software

VendorProductVersion RangeStatus
IBMLangflow OSS1.0.0 <= 1.11.5affected

Weaknesses

  • CWE-78: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

References