Vulnerabilities
Vulnerable Software
Security Vulnerabilities
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbitrary files due to path traversal.
CVSS Score
7.5
EPSS Score
0.005
Published
2026-08-28
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint.
CVSS Score
9.8
EPSS Score
0.006
Published
2026-08-28
IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references it. This allowed privilege escalation from "authenticated flow user" to arbitrary OS-level command execution under the server process identity, bypassing the LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false policy control.
CVSS Score
9.9
EPSS Score
0.01
Published
2026-08-28
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.
CVSS Score
8.8
EPSS Score
0.005
Published
2026-08-28
A flaw was found in the file-psd plugin in GIMP. When processing a specially crafted PSD image file, the plugin does not properly validate the channel-count parameter. This incorrect validation leads to improper memory bounds checking, resulting in both a heap out-of-bounds read and a stack out-of-bounds access. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of memory contents.
CVSS Score
6.1
EPSS Score
0.001
Published
2026-08-28
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVSS Score
8.8
EPSS Score
0.004
Published
2026-08-28
Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.
CVSS Score
5.4
EPSS Score
0.003
Published
2026-08-28
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
CVSS Score
5.4
EPSS Score
0.002
Published
2026-08-28
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVSS Score
4.3
EPSS Score
0.006
Published
2026-08-28
Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network.
CVSS Score
4.4
EPSS Score
0.002
Published
2026-08-28


Contact Us

Shodan ® - All rights reserved