Threat reportVulnerabilityTL-2026-3314
IBM Langflow OSS Multiple Vulnerabilities Including Two Critical Unauthenticated RCE Flaws (CVE-2026-104334, CVE-2026-93674)
IBM Langflow OSS Multiple Vulnerabilities Including Two (TL-2026-3314) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-10-11. It has no confirmed attribution, affects IBM Langflow OSS, references 25 CVEs (CVE-2026-104334, CVE-2026-93674, CVE-2026-97676), maps to 10 MITRE ATT&CK techniques (T1005, T1059, T1059.004), and is covered by 9 detection rules and 9 indicators of compromise.
- CVSS
- 9.8/10Critical
- CVEs
- 25Referenced vulnerabilities
- Techniques
- 10MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 9Indicators of compromise
Key facts for TL-2026-3314
- Threat ID
- TL-2026-3314
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, ai-ml, software-development
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 9
Malware and tooling in IBM Langflow OSS Multiple Vulnerabilities Including Two
Malware and tooling: Python, Langflow
How IBM Langflow OSS Multiple Vulnerabilities Including Two works
IBM patched 25 vulnerabilities in Langflow OSS 1.0.0 through 1.12.2, including two unauthenticated critical code/command injection flaws (CVE-2026-104334, CVE-2026-93674; CVSS 9.8). Fixes ship in Langflow 1.12.3 and 1.12.4; IBM lists no workarounds and no in-the-wild exploitation was reported.
IBM Security Bulletin 7290694 (published 2026-10-02) discloses 25 vulnerabilities in Langflow OSS, the visual platform for building AI agents and workflows with Python-customizable components and built-in API/MCP server capabilities. Affected versions are 1.0.0 through 1.12.2. Per secondary reporting, 2 are critical, 19 high and 4 medium/low, and 15 can lead to code execution.
The two critical flaws are CVE-2026-104334 (improper control of code generation, remote code execution) and CVE-2026-93674 (improper neutralization of special elements in an OS command). Both are scored CVSS 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and are described by IBM as exploitable by a remote unauthenticated attacker with no user interaction. IBM maps both to CWE-94.
The remaining flaws (CVSS 4.3-8.8) include authenticated sandbox escape via code injection (CVE-2026-97676), a code-security-scanner incomplete-blocklist bypass (CVE-2026-97655), code execution through code-generation control failures (CVE-2026-88962, CVE-2026-93449, CVE-2026-97679, CVE-2026-97674, CVE-2026-93443), improper input validation (CVE-2026-97678, CVE-2026-97673), an access-control execution flaw (CVE-2026-104335), dependency confusion enabling code execution that requires user interaction (CVE-2026-93675), untrusted deserialization of cached data (CVE-2026-93447; per SecurityOnline it requires the server secret and Redis write access), path traversal and arbitrary file read/write (CVE-2026-97677, CVE-2026-103360, CVE-2026-97671, CVE-2026-93448), cache access-control failure (CVE-2026-97680), authorization bypass and information exposure (CVE-2026-93678, CVE-2026-93677, CVE-2026-101329), insufficiently protected credentials (CVE-2026-101331), and ZIP-extraction resource exhaustion DoS (CVE-2026-93679). CVE-2026-97677 is reported to allow writes to any directory writable by the service account and reads of configuration files, secrets or databases.
Exploitation status: GBHackers and the IBM bulletin report no evidence of active exploitation or public exploits, and the flaws are not reported in CISA KEV. Caveat: TheHackerWire references a GitHub repository (rmhowe425/POC-CVE-2026-93674) described as an authenticated blind command-injection PoC for Langflow (poc.py, takes URL, username, password and a shell command). It requires valid credentials, so it does not match IBM's unauthenticated characterization, and its relation to the CVE is unverified. The exploitability field is therefore set to POC_PUBLIC with low confidence. The bulletin lists 25 CVEs; the hunt skeleton enumerated 24, and CVE-2026-103360 (path traversal, CVSS 8.1) comes from the IBM bulletin. Version note: IBM states 1.0.0-1.12.2 affected with 1.12.3 (2026-09-22) as the fix; GBHackers also cites 1.12.4 (2026-09-29). One summary lists 1.12.3 as affected, which conflicts with IBM, so upgrade to 1.12.4 is the safest guidance. No actor, campaign, C2 infrastructure or network IOCs are associated with these flaws, so no BeaconBeagle correlation was applicable.
MITRE ATT&CK techniques used in TL-2026-3314
Collection
Execution
T1059 Command and Scripting Interpreter; T1059.004 Unix Shell; T1059.006 Python; T1204 User Execution
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application; T1195.001 Compromise Software Dependencies and Development Tools
Credential Access
T1552.001 Credentials In Files
Impact
Affected products and versions in IBM Langflow OSS Multiple Vulnerabilities Including Two
- IBM — Langflow OSS
Vulnerable versions: 1.0.0 through 1.12.2
Fixed in: 1.12.3; 1.12.4
Remediation for IBM Langflow OSS Multiple Vulnerabilities Including Two
Patches
- Langflow OSS 1.12.3 (released 2026-09-22)
- Langflow OSS 1.12.4 (released 2026-09-29)
- IBM Security Bulletin https://www.ibm.com/support/pages/node/7290694
Immediate actions
- Upgrade Langflow OSS to 1.12.4 (1.12.3 is the minimum fixed version named in the IBM bulletin)
- Remove internet exposure of Langflow instances until patched and restrict access to trusted networks
- Rotate API keys, secrets and credentials stored in or reachable from Langflow after patching
Workarounds
- None provided by IBM
Longer-term hardening
- Run Langflow under a least-privilege service account, since path traversal flaws can write to any directory the account can write
- Restrict Redis write access and protect the server secret used for cache serialization
- Vet third-party packages and component dependencies to reduce dependency confusion risk
- Monitor Langflow process trees for unexpected shell or interpreter child processes
CVEs associated with IBM Langflow OSS Multiple Vulnerabilities Including Two
- CVE-2026-104334
- CVE-2026-93674
- CVE-2026-97676
- CVE-2026-97677
- CVE-2026-97680
- CVE-2026-97678
- CVE-2026-97673
- CVE-2026-97674
- CVE-2026-88962
- CVE-2026-93675
- CVE-2026-104335
- CVE-2026-93449
- CVE-2026-97655
- CVE-2026-97679
- CVE-2026-93445
- CVE-2026-93678
- CVE-2026-93677
- CVE-2026-101331
- CVE-2026-93443
- CVE-2026-93447
- CVE-2026-101329
- CVE-2026-93448
- CVE-2026-97671
- CVE-2026-93679
- CVE-2026-103360
Weaknesses (CWE) in IBM Langflow OSS Multiple Vulnerabilities Including Two
CWE-94, CWE-22, CWE-284, CWE-693, CWE-440, CWE-522, CWE-639, CWE-200, CWE-502, CWE-400
Timeline of IBM Langflow OSS Multiple Vulnerabilities Including Two
- Langflow OSS 1.12.3 released, the first version containing fixes for the disclosed flaws
- Langflow OSS 1.12.4 released with additional fixes
- IBM publishes Security Bulletin 7290694 covering Langflow OSS 1.0.0 through 1.12.2, listing two critical CVSS 9.8 unauthenticated RCE flaws and no workarounds
- SecurityOnline publishes analysis: 15 of 25 flaws lead to code execution; advises restricting internet exposure, limiting flow creation/editing permissions and rotating API keys after patching
- GBHackers reports IBM's patches for 25 Langflow OSS vulnerabilities, with no evidence of active exploitation or public exploits
- NVD record for CVE-2026-104334 published (CVSS 3.1 9.8, CWE-94), listing Langflow 1.0.0 through 1.12.2 as vulnerable and 1.12.3 and later as fixed
- CVE-2026-93674 record published; TheHackerWire references a third-party GitHub PoC (authenticated blind command injection), reports EPSS 2.66% and notes the CVE is not in CISA KEV
Sources cited for IBM Langflow OSS Multiple Vulnerabilities Including Two
- IBM Security Bulletin: Langflow OSS vulnerabilities
- IBM Patches Multiple Langflow OSS Flaws Including Two Critical RCE Vulnerabilities (GBHackers)
- Langflow vulnerabilities fixed in 1.12.3 (SecurityOnline)
- CVE-2026-93674 (TheHackerWire)
- CVE-2026-104334 IBM Langflow OSS code generation flaw enables remote arbitrary code execution (TheHackerWire)
- POC-CVE-2026-93674 (authenticated blind command injection PoC; relation to CVE unverified)
Detection coverage for TL-2026-3314
As of 2026-10-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3314 across Splunk SPL, Microsoft KQL and Sigma, covering 9 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.