chiprook
← Security
SecuritySeptember 16, 2026, 10:19

Langflow CVE-2026-12944: Scanner Blocklist Gap Leads to Root Code Execution

Langflow OSS has a critical vulnerability CVE-2026-12944 (CVSS 9.6): the component scanner blocks subprocess but misses socket and urllib, allowing an authenticated user to execute code as root. Versions 1.0.0–1.10.0 are affected; fix is 1.10.3.

Langflow CVE-2026-12944: Scanner Blocklist Gap Leads to Root Code Execution
#Langflow#IBM
Read next
Security

Contagious Interview Campaign Hits 30,000 Devices, Steals $10.71M in Crypto

Security

Google Releases AndroidX Libraries for Granular Android Patch Checks

Security

Surfshark: iPhone lets you delete 98% of preinstalled apps, Google only 38%

Security

Hackers extract 1.6 million images and 27,000 videos from a single Flock camera