# IBM Langflow OSS Multiple Vulnerabilities Including Two Critical Unauthenticated RCE Flaws (CVE-2026-104334, CVE-2026-93674)

> IBM patched 25 vulnerabilities in Langflow OSS 1.0.0 through 1.12.2, including two unauthenticated critical code/command injection flaws (CVE-2026-104334, CVE-2026-93674; CVSS 9.8). Fixes ship in Langflow 1.12.3 and 1.12.4; IBM lists no workarounds and no in-the-wild exploitation was reported.

- **Published:** 2026-10-11T15:05:52Z
- **Last reviewed:** 2026-10-11T15:05:52Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3314
- **ID:** TL-2026-3314
- **Severity:** CRITICAL (CVSS 9.8)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 9 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-104334, CVE-2026-93674, CVE-2026-97676, CVE-2026-97677, CVE-2026-97680, CVE-2026-97678, CVE-2026-97673, CVE-2026-97674, CVE-2026-88962, CVE-2026-93675, CVE-2026-104335, CVE-2026-93449, CVE-2026-97655, CVE-2026-97679, CVE-2026-93445, CVE-2026-93678, CVE-2026-93677, CVE-2026-101331, CVE-2026-93443, CVE-2026-93447, CVE-2026-101329, CVE-2026-93448, CVE-2026-97671, CVE-2026-93679, CVE-2026-103360

## Description

IBM Security Bulletin 7290694 (published 2026-10-02) discloses 25 vulnerabilities in Langflow OSS, the visual platform for building AI agents and workflows with Python-customizable components and built-in API/MCP server capabilities. Affected versions are 1.0.0 through 1.12.2. Per secondary reporting, 2 are critical, 19 high and 4 medium/low, and 15 can lead to code execution.

The two critical flaws are CVE-2026-104334 (improper control of code generation, remote code execution) and CVE-2026-93674 (improper neutralization of special elements in an OS command). Both are scored CVSS 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and are described by IBM as exploitable by a remote unauthenticated attacker with no user interaction. IBM maps both to CWE-94.

The remaining flaws (CVSS 4.3-8.8) include authenticated sandbox escape via code injection (CVE-2026-97676), a code-security-scanner incomplete-blocklist bypass (CVE-2026-97655), code execution through code-generation control failures (CVE-2026-88962, CVE-2026-93449, CVE-2026-97679, CVE-2026-97674, CVE-2026-93443), improper input validation (CVE-2026-97678, CVE-2026-97673), an access-control execution flaw (CVE-2026-104335), dependency confusion enabling code execution that requires user interaction (CVE-2026-93675), untrusted deserialization of cached data (CVE-2026-93447; per SecurityOnline it requires the server secret and Redis write access), path traversal and arbitrary file read/write (CVE-2026-97677, CVE-2026-103360, CVE-2026-97671, CVE-2026-93448), cache access-control failure (CVE-2026-97680), authorization bypass and information exposure (CVE-2026-93678, CVE-2026-93677, CVE-2026-101329), insufficiently protected credentials (CVE-2026-101331), and ZIP-extraction resource exhaustion DoS (CVE-2026-93679). CVE-2026-97677 is reported to allow writes to any directory writable by the service account and reads of configuration files, secrets or databases.

Exploitation status: GBHackers and the IBM bulletin report no evidence of active exploitation or public exploits, and the flaws are not reported in CISA KEV. Caveat: TheHackerWire references a GitHub repository (rmhowe425/POC-CVE-2026-93674) described as an authenticated blind command-injection PoC for Langflow (poc.py, takes URL, username, password and a shell command). It requires valid credentials, so it does not match IBM's unauthenticated characterization, and its relation to the CVE is unverified. The exploitability field is therefore set to POC_PUBLIC with low confidence. The bulletin lists 25 CVEs; the hunt skeleton enumerated 24, and CVE-2026-103360 (path traversal, CVSS 8.1) comes from the IBM bulletin. Version note: IBM states 1.0.0-1.12.2 affected with 1.12.3 (2026-09-22) as the fix; GBHackers also cites 1.12.4 (2026-09-29). One summary lists 1.12.3 as affected, which conflicts with IBM, so upgrade to 1.12.4 is the safest guidance. No actor, campaign, C2 infrastructure or network IOCs are associated with these flaws, so no BeaconBeagle correlation was applicable.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1195.001 Compromise Software Dependencies and Development Tools
- T1059 Command and Scripting Interpreter
- T1059.006 Python
- T1059.004 Unix Shell
- T1552.001 Credentials In Files
- T1005 Data from Local System
- T1204 User Execution
- T1565.001 Stored Data Manipulation

## Sources

- [IBM Security Bulletin: Langflow OSS vulnerabilities](https://www.ibm.com/support/pages/node/7290694)
- [IBM Patches Multiple Langflow OSS Flaws Including Two Critical RCE Vulnerabilities (GBHackers)](https://gbhackers.com/ibm-patches-multiple-langflow-oss-flaws/)
- [Langflow vulnerabilities fixed in 1.12.3 (SecurityOnline)](https://securityonline.info/langflow-vulnerabilities-1-12-3/)
- [CVE-2026-93674 (TheHackerWire)](https://www.thehackerwire.com/vulnerability/CVE-2026-93674/)
- [CVE-2026-104334 IBM Langflow OSS code generation flaw enables remote arbitrary code execution (TheHackerWire)](https://www.thehackerwire.com/cve-2026-104334-ibm-langflow-oss-code-generation-flaw-enables-remote-arbitrary-code-execution/)
- [POC-CVE-2026-93674 (authenticated blind command injection PoC; relation to CVE unverified)](https://github.com/rmhowe425/POC-CVE-2026-93674)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3314
