• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-12940: unauthenticated remote code execution in IBM Langflow OSS

Remote, unauthenticated attackers can achieve remote code execution against IBM Langflow OSS by supplying crafted environment variables that are processed by the MCP stdio launcher; this issue is tracked as CVE-2026-12940. The vulnerability affects Langflow OSS releases from 1.0.0 through 1.10.1. An attacker only needs a way to influence the environment of the affected launcher component — no valid credentials or user interaction are required — to execute arbitrary commands on the host running the service.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00943
CWE
CWE-78
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code exists, so prioritize reducing internet exposure and applying vendor guidance or mitigations immediately to vulnerable Langflow OSS instances.

What is CVE-2026-12940?

Remote, unauthenticated attackers can achieve remote code execution against IBM Langflow OSS by supplying crafted environment variables that are processed by the MCP stdio launcher; this issue is tracked as CVE-2026-12940. The vulnerability affects Langflow OSS releases from 1.0.0 through 1.10.1. An attacker only needs a way to influence the environment of the affected launcher component — no valid credentials or user interaction are required — to execute arbitrary commands on the host running the service. The weakness is classified as CWE-78 (OS Command Injection).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of IBM Langflow OSS are affected?

BRANCHAFFECTEDFIXED
1.x1.0.0 – 1.10.1

Is CVE-2026-12940 being exploited?

Public exploit code is available.

How to fix CVE-2026-12940

  1. Remove or restrict external network access to Langflow OSS and the MCP stdio launcher immediately.
  2. Follow IBM's official advisory and apply vendor-supplied updates or mitigation steps as soon as they publish fixed releases for the 1.x branch.
  3. Harden service configuration to prevent untrusted sources from setting environment variables consumed by the MCP stdio launcher.
  4. Monitor system and application logs for unexpected child processes or shell invocations originating from Langflow components.

Frequently asked questions

Is CVE-2026-12940 being actively exploited?

Public exploit code is available for CVE-2026-12940, which increases the likelihood of active exploitation against IBM Langflow OSS instances.

Which Langflow OSS versions are affected by CVE-2026-12940?

Langflow OSS versions 1.0.0 through 1.10.1 are affected by CVE-2026-12940.

Is there a patch for CVE-2026-12940?

A patch is reported as available overall, but no specific fixed 1.x release is listed for the affected 1.0.0–1.10.1 branch in the provided facts; follow IBM's official updates for exact fixed version numbers and deploy them when published.

Does CVE-2026-12940 require authentication?

No. CVE-2026-12940 can be exploited without authentication, allowing remote code execution in IBM Langflow OSS without credentials.

References