Langflow CVE-2026-12944: Scanner Blocklist Gap Leads to Root Code Execution
Langflow OSS has a critical vulnerability CVE-2026-12944 (CVSS 9.6): the component scanner blocks subprocess but misses socket and urllib, allowing an authenticated user to execute code as root. Versions 1.0.0–1.10.0 are affected; fix is 1.10.3.
- CVE-2026-12944: CVSS 9.6, affects Langflow OSS 1.0.0–1.10.0
- Scanner blocks subprocess but misses socket and urllib
- Code executes with root privileges in Langflow container
- Second flaw CVE-2026-17628 (CVSS 5.4) allows password reset without old password
Read next
Security