Threat reportVulnerabilityTL-2026-3314

IBM Langflow OSS Multiple Vulnerabilities Including Two Critical Unauthenticated RCE Flaws (CVE-2026-104334, CVE-2026-93674)

criticalPATCHED

IBM Langflow OSS Multiple Vulnerabilities Including Two (TL-2026-3314) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-10-11. It has no confirmed attribution, affects IBM Langflow OSS, references 25 CVEs (CVE-2026-104334, CVE-2026-93674, CVE-2026-97676), maps to 10 MITRE ATT&CK techniques (T1005, T1059, T1059.004), and is covered by 9 detection rules and 9 indicators of compromise.

CVSS
9.8/10Critical
CVEs
25Referenced vulnerabilities
Techniques
10MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
9Indicators of compromise

Key facts for TL-2026-3314

Threat ID
TL-2026-3314
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, ai-ml, software-development
Target regions
Global
Detection rules
9
Indicators of compromise
9

Malware and tooling in IBM Langflow OSS Multiple Vulnerabilities Including Two

Malware and tooling: Python, Langflow

How IBM Langflow OSS Multiple Vulnerabilities Including Two works

IBM patched 25 vulnerabilities in Langflow OSS 1.0.0 through 1.12.2, including two unauthenticated critical code/command injection flaws (CVE-2026-104334, CVE-2026-93674; CVSS 9.8). Fixes ship in Langflow 1.12.3 and 1.12.4; IBM lists no workarounds and no in-the-wild exploitation was reported.

IBM Security Bulletin 7290694 (published 2026-10-02) discloses 25 vulnerabilities in Langflow OSS, the visual platform for building AI agents and workflows with Python-customizable components and built-in API/MCP server capabilities. Affected versions are 1.0.0 through 1.12.2. Per secondary reporting, 2 are critical, 19 high and 4 medium/low, and 15 can lead to code execution.

The two critical flaws are CVE-2026-104334 (improper control of code generation, remote code execution) and CVE-2026-93674 (improper neutralization of special elements in an OS command). Both are scored CVSS 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and are described by IBM as exploitable by a remote unauthenticated attacker with no user interaction. IBM maps both to CWE-94.

The remaining flaws (CVSS 4.3-8.8) include authenticated sandbox escape via code injection (CVE-2026-97676), a code-security-scanner incomplete-blocklist bypass (CVE-2026-97655), code execution through code-generation control failures (CVE-2026-88962, CVE-2026-93449, CVE-2026-97679, CVE-2026-97674, CVE-2026-93443), improper input validation (CVE-2026-97678, CVE-2026-97673), an access-control execution flaw (CVE-2026-104335), dependency confusion enabling code execution that requires user interaction (CVE-2026-93675), untrusted deserialization of cached data (CVE-2026-93447; per SecurityOnline it requires the server secret and Redis write access), path traversal and arbitrary file read/write (CVE-2026-97677, CVE-2026-103360, CVE-2026-97671, CVE-2026-93448), cache access-control failure (CVE-2026-97680), authorization bypass and information exposure (CVE-2026-93678, CVE-2026-93677, CVE-2026-101329), insufficiently protected credentials (CVE-2026-101331), and ZIP-extraction resource exhaustion DoS (CVE-2026-93679). CVE-2026-97677 is reported to allow writes to any directory writable by the service account and reads of configuration files, secrets or databases.

Exploitation status: GBHackers and the IBM bulletin report no evidence of active exploitation or public exploits, and the flaws are not reported in CISA KEV. Caveat: TheHackerWire references a GitHub repository (rmhowe425/POC-CVE-2026-93674) described as an authenticated blind command-injection PoC for Langflow (poc.py, takes URL, username, password and a shell command). It requires valid credentials, so it does not match IBM's unauthenticated characterization, and its relation to the CVE is unverified. The exploitability field is therefore set to POC_PUBLIC with low confidence. The bulletin lists 25 CVEs; the hunt skeleton enumerated 24, and CVE-2026-103360 (path traversal, CVSS 8.1) comes from the IBM bulletin. Version note: IBM states 1.0.0-1.12.2 affected with 1.12.3 (2026-09-22) as the fix; GBHackers also cites 1.12.4 (2026-09-29). One summary lists 1.12.3 as affected, which conflicts with IBM, so upgrade to 1.12.4 is the safest guidance. No actor, campaign, C2 infrastructure or network IOCs are associated with these flaws, so no BeaconBeagle correlation was applicable.

MITRE ATT&CK techniques used in TL-2026-3314

Collection

T1005 Data from Local System

Execution

T1059 Command and Scripting Interpreter; T1059.004 Unix Shell; T1059.006 Python; T1204 User Execution

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application; T1195.001 Compromise Software Dependencies and Development Tools

Credential Access

T1552.001 Credentials In Files

Impact

T1565.001 Stored Data Manipulation

Affected products and versions in IBM Langflow OSS Multiple Vulnerabilities Including Two

  • IBM — Langflow OSS
    Vulnerable versions: 1.0.0 through 1.12.2
    Fixed in: 1.12.3; 1.12.4

Remediation for IBM Langflow OSS Multiple Vulnerabilities Including Two

Patches

  • Langflow OSS 1.12.3 (released 2026-09-22)
  • Langflow OSS 1.12.4 (released 2026-09-29)
  • IBM Security Bulletin https://www.ibm.com/support/pages/node/7290694

Immediate actions

  • Upgrade Langflow OSS to 1.12.4 (1.12.3 is the minimum fixed version named in the IBM bulletin)
  • Remove internet exposure of Langflow instances until patched and restrict access to trusted networks
  • Rotate API keys, secrets and credentials stored in or reachable from Langflow after patching

Workarounds

  • None provided by IBM

Longer-term hardening

  • Run Langflow under a least-privilege service account, since path traversal flaws can write to any directory the account can write
  • Restrict Redis write access and protect the server secret used for cache serialization
  • Vet third-party packages and component dependencies to reduce dependency confusion risk
  • Monitor Langflow process trees for unexpected shell or interpreter child processes

CVEs associated with IBM Langflow OSS Multiple Vulnerabilities Including Two

Weaknesses (CWE) in IBM Langflow OSS Multiple Vulnerabilities Including Two

CWE-94, CWE-22, CWE-284, CWE-693, CWE-440, CWE-522, CWE-639, CWE-200, CWE-502, CWE-400

Timeline of IBM Langflow OSS Multiple Vulnerabilities Including Two

  • Langflow OSS 1.12.3 released, the first version containing fixes for the disclosed flaws
  • Langflow OSS 1.12.4 released with additional fixes
  • IBM publishes Security Bulletin 7290694 covering Langflow OSS 1.0.0 through 1.12.2, listing two critical CVSS 9.8 unauthenticated RCE flaws and no workarounds
  • SecurityOnline publishes analysis: 15 of 25 flaws lead to code execution; advises restricting internet exposure, limiting flow creation/editing permissions and rotating API keys after patching
  • GBHackers reports IBM's patches for 25 Langflow OSS vulnerabilities, with no evidence of active exploitation or public exploits
  • NVD record for CVE-2026-104334 published (CVSS 3.1 9.8, CWE-94), listing Langflow 1.0.0 through 1.12.2 as vulnerable and 1.12.3 and later as fixed
  • CVE-2026-93674 record published; TheHackerWire references a third-party GitHub PoC (authenticated blind command injection), reports EPSS 2.66% and notes the CVE is not in CISA KEV

Sources cited for IBM Langflow OSS Multiple Vulnerabilities Including Two

Detection coverage for TL-2026-3314

As of 2026-10-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3314 across Splunk SPL, Microsoft KQL and Sigma, covering 9 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
9 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats