• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-12944: authenticated remote code execution in IBM Langflow OSS

An attacker with a low-privilege account can run arbitrary Python code as root on an IBM Langflow OSS server, enabling full compromise of the container and access to internal services. CVE-2026-12944 affects Langflow OSS versions 1.0.0 through 1.10.0; exploitation occurs when specially crafted components that import socket or urllib are submitted. The vulnerability requires network access and a low-privilege (PR:L) account, and it does not require user interaction.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.6CRITICAL
EPSS
0.00429
CWE
CWE-918
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code exists, so assume easy weaponization; prioritize applying the vendor's remediation and remove or restrict internet-facing access to Langflow servers immediately.

What is CVE-2026-12944?

An attacker with a low-privilege account can run arbitrary Python code as root on an IBM Langflow OSS server, enabling full compromise of the container and access to internal services. CVE-2026-12944 affects Langflow OSS versions 1.0.0 through 1.10.0; exploitation occurs when specially crafted components that import socket or urllib are submitted. The vulnerability requires network access and a low-privilege (PR:L) account, and it does not require user interaction. The weakness is classified as CWE-918 (Server-Side Request Forgery).

Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Which versions of IBM Langflow OSS are affected?

BRANCHAFFECTEDFIXED
1.x1.0.0 – 1.10.0

Is CVE-2026-12944 being exploited?

Public exploit code is available.

How to fix CVE-2026-12944

  1. Apply vendor guidance or vendor-supplied update as soon as it is published or recommended.
  2. Restrict network exposure of Langflow instances to trusted networks and block untrusted uploads or component submissions.
  3. Rotate and revoke any credentials or tokens that could be exposed (cloud metadata credentials, service accounts).
  4. Monitor Langflow and container logs for unexpected component submissions, imports of socket/urllib, and root-level process execution.

Frequently asked questions

Is CVE-2026-12944 being actively exploited?

Public exploit code is available for CVE-2026-12944.

Which Langflow OSS versions are affected by CVE-2026-12944?

Langflow OSS versions 1.0.0 through 1.10.0 are affected by CVE-2026-12944.

Is there a patch for CVE-2026-12944?

A vendor patch or guidance is available according to the facts, but no fixed version numbers are listed for the affected 1.x branch; apply the vendor guidance immediately.

Does CVE-2026-12944 require authentication?

Yes. Exploitation requires a low-privilege authenticated account on the Langflow OSS server.

References