CVE-2026-97679

Summary

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command ('Code Injection') related to improper input validation.

Affected Software

VendorProductVersion RangeStatus
IBMLangflow OSS1.0.0 <= 1.12.2affected

Weaknesses

  • CWE-94: CWE-94 Improper Control of Generation of Code ('Code Injection')

References