chiprook
← Security
SecurityOctober 11, 2026, 13:40

IBM finds 25 Langflow flaws, including sandbox escape

IBM published a security bulletin covering 25 vulnerabilities in Langflow OSS 1.0.0–1.12.2: 2 critical without login, 19 high and 4 medium, with 15 leading to code execution. Sandbox escape CVE-2026-97676 and scanner bypass CVE-2026-97655 need only an account. Fix is upgrading to 1.12.3.

IBM finds 25 Langflow flaws, including sandbox escape
#IBM#Langflow
Read next
Security

Three Langflow flaws rated CVSS 9.8 allow unauthenticated RCE

Security

IBM patches 12 flaws in MQ and Langflow OSS, three rated 9.8

Security

CVE-2026-17633: Authenticated RCE in Langflow OSS via /api/v1/custom_component

Security

Langflow CVE-2026-12944: Scanner Blocklist Gap Leads to Root Code Execution