chiprook
← Security
SecuritySeptember 22, 2026, 06:06

CVE-2026-17633: Authenticated RCE in Langflow OSS via /api/v1/custom_component

Langflow OSS 1.0.0–1.10.3 contains CVE-2026-17633 (CVSS 8.5), an authenticated RCE reachable through the /api/v1/custom_component endpoint. The flaw is in prepare_global_scope(): code inside a class body executes during exec(), and the scan_code_security() scanner is never called on this path. Fixed in 1.10.4.

CVE-2026-17633: Authenticated RCE in Langflow OSS via /api/v1/custom_component
#Langflow#IBM
Read next
Security

American Airlines Laptop Fire Could Reshape Airplane Safety and Insurance

Security

NIST FRTE 1:1 update shows shifting leaders, persistent demographic disparities

Security

LoRD uses heuristics to detect hardware Trojans in synthesized netlists

Security

Hackers hide malware commands in blockchains as malicious activity jumps 440%