• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-18729: authenticated remote code execution in IBM Langflow OSS

A remote, authenticated user can execute arbitrary code on Langflow OSS, creating a full compromise of affected deployments; this is tracked as CVE-2026-18729. The issue affects Langflow OSS versions 1.0.0 through 1.11.1 and stems from improper control over generated code. An attacker needs network access to the service and valid credentials (an authenticated account) to exploit the flaw.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
8.8HIGH
EPSS
0.01946
CWE
CWE-94
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code exists, so prioritize mitigation now by restricting access and applying vendor guidance where available.

What is CVE-2026-18729?

A remote, authenticated user can execute arbitrary code on Langflow OSS, creating a full compromise of affected deployments; this is tracked as CVE-2026-18729. The issue affects Langflow OSS versions 1.0.0 through 1.11.1 and stems from improper control over generated code. An attacker needs network access to the service and valid credentials (an authenticated account) to exploit the flaw.

Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of IBM Langflow OSS are affected?

BRANCHAFFECTEDFIXED
1.x1.0.0 – 1.11.1

Is CVE-2026-18729 being exploited?

Public exploit code is available.

How to fix CVE-2026-18729

  1. Restrict network exposure of Langflow OSS instances to trusted hosts and networks.
  2. Require strong authentication and rotate any exposed credentials or API keys tied to Langflow.
  3. Apply the vendor's guidance or vendor-supplied patch as soon as it is published.
  4. Monitor Langflow logs and host indicators for suspicious code execution or unexpected processes.

Frequently asked questions

Is CVE-2026-18729 being actively exploited?

Public exploit code is available for CVE-2026-18729; CISA has not listed it in the KEV catalog as of 2026-09-29.

Which Langflow OSS versions are affected by CVE-2026-18729?

Langflow OSS versions 1.0.0 through 1.11.1 are affected by CVE-2026-18729.

Is there a patch for CVE-2026-18729?

A patch is reported available for CVE-2026-18729; however, fixed version identifiers were not provided in the available facts, so follow IBM's official advisory for exact remediation steps.

Does CVE-2026-18729 require authentication?

Yes. Exploitation of CVE-2026-18729 requires an authenticated account on the Langflow OSS instance.

References