DIRAS TAKE
Urgent: public exploit code exists for this authenticated code-injection flaw, so exposed Langflow OSS instances should be isolated or remediated immediately. Treat internet-facing installations and shared environments as highest priority because an attacker only needs an account and network access.
What is CVE-2026-17633?
A remote authenticated attacker can execute arbitrary code on Langflow OSS; this vulnerability is tracked as CVE-2026-17633. Affects Langflow OSS branch 1.x, versions 1.0.0 through 1.10.3. Exploitation requires an account on the application (low privilege is sufficient) and network access to the vulnerable service. The flaw is a code injection issue (CWE-94) that can lead to full confidentiality, integrity, and availability loss on affected systems.
Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Which versions of IBM Langflow OSS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 1.x | 1.0.0 – 1.10.3 |
Is CVE-2026-17633 being exploited?
Public exploit code is available.
How to fix CVE-2026-17633
- Apply the vendor's patch or update guidance as soon as it is available for Langflow OSS.
- Block or restrict network access to Langflow OSS instances from untrusted networks and the internet.
- Review and harden user accounts: remove unused accounts, enforce least privilege, and rotate credentials.
- Monitor Langflow OSS logs and system processes for unexpected code execution or suspicious activity.
Frequently asked questions
Is CVE-2026-17633 being actively exploited?
Public exploit code is available for CVE-2026-17633.
Which Langflow OSS versions are affected by CVE-2026-17633?
Langflow OSS branch 1.x, versions 1.0.0 through 1.10.3 are listed as affected.
Is there a patch for CVE-2026-17633?
A vendor patch is reported to be available; follow IBM's Langflow OSS update guidance to obtain and apply the fix.
Does CVE-2026-17633 require authentication?
Yes. Exploitation of CVE-2026-17633 requires an authenticated account on the Langflow OSS instance, with low privilege sufficient.
References
- nvd.nist.gov/vuln/detail/CVE-2026-17633
- cve.org/CVERecord?id=CVE-2026-17633
- ibm.com/support/pages/node/7282646
- All IBM CVEs on CVE Radar
- CVEs published in September 2026