Vulnerabilities
Vulnerable Software
Security Vulnerabilities
IBM Langflow OSS 1.0.0 through 1.11.5.
CVSS Score
7.5
EPSS Score
0.002
Published
2026-09-10
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation.
CVSS Score
8.1
EPSS Score
0.003
Published
2026-09-10
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction.
CVSS Score
9.8
EPSS Score
0.006
Published
2026-09-10
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows.
CVSS Score
8.8
EPSS Score
0.003
Published
2026-09-10
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the MCP stdio server configuration.
CVSS Score
8.8
EPSS Score
0.005
Published
2026-09-10
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-controlled API endpoints.
CVSS Score
5.0
EPSS Score
0.002
Published
2026-09-10
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.
CVSS Score
9.8
EPSS Score
0.005
Published
2026-09-10
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to read arbitrary files due to improper access control.
CVSS Score
6.5
EPSS Score
0.003
Published
2026-09-10
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist.
CVSS Score
8.8
EPSS Score
0.006
Published
2026-09-10
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.27 could allow a remote authenticated attacker to bypass security restrictions due to incorrect authorization.
CVSS Score
8.8
EPSS Score
0.004
Published
2026-09-10


Contact Us

Shodan ® - All rights reserved