IBM finds 25 Langflow flaws, including sandbox escape
IBM published a security bulletin covering 25 vulnerabilities in Langflow OSS 1.0.0–1.12.2: 2 critical without login, 19 high and 4 medium, with 15 leading to code execution. Sandbox escape CVE-2026-97676 and scanner bypass CVE-2026-97655 need only an account. Fix is upgrading to 1.12.3.
- 25 flaws in Langflow OSS 1.0.0–1.12.2: 2 critical, 19 high, 4 medium
- 15 flaws allow code execution; CVE-2026-93675 scores CVSS 8.8
- CVE-2026-97676 escapes the sandbox, CVE-2026-97655 bypasses the code scanner
- Recommended: upgrade to 1.12.3, rotate keys and keep instances off the public internet
Read next
Security