Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-8481

IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts user-supplied Python code and executes it directly using Python's built-in exec() function without sandboxing, input validation, or privilege restrictions, enabling any authenticated user to execute arbitrary system commands with the full privileges of the Langflow server process.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 35.6%
CVSS Severity
CVSS v3 Score 9.9
Products affected by CVE-2026-8481


Contact Us

Shodan ® - All rights reserved