• PATCH AVAILABLE

CVE-2026-79724: pre-auth command injection in IBM Langflow OSS

An unauthenticated remote attacker can execute arbitrary operating system commands on IBM Langflow OSS, resulting in full confidentiality, integrity, and availability impact (CVE-2026-79724). The flaw is a command injection (CWE-78) that affects Langflow OSS versions 1.0.0 through 1.11.5; an attacker only needs network access to a vulnerable Langflow OSS instance to exploit it because no privileges or user interaction are required.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00673
CWE
CWE-78
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is a remote, unauthenticated command injection with critical impact (CVSS 9.8); prioritize isolating internet-facing Langflow OSS instances and apply vendor fixes or mitigations immediately.

What is CVE-2026-79724?

An unauthenticated remote attacker can execute arbitrary operating system commands on IBM Langflow OSS, resulting in full confidentiality, integrity, and availability impact (CVE-2026-79724). The flaw is a command injection (CWE-78) that affects Langflow OSS versions 1.0.0 through 1.11.5; an attacker only needs network access to a vulnerable Langflow OSS instance to exploit it because no privileges or user interaction are required. The weakness is classified as CWE-78 (OS Command Injection).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of IBM Langflow OSS are affected?

BRANCHAFFECTEDFIXED
1.x1.0.0 – 1.11.5

Is CVE-2026-79724 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-79724

  1. Apply the vendor-provided patch or guidance immediately (vendor has indicated a patch is available).
  2. If a fixed package is not yet deployed, restrict network access to Langflow OSS instances to trusted hosts only.
  3. Monitor application and host logs for suspicious command execution and anomalous process activity.
  4. Follow vendor guidance for configuration changes or temporary mitigations until patched.

Frequently asked questions

Is CVE-2026-79724 being actively exploited?

There are no public reports of exploitation of CVE-2026-79724 as of 2026-09-29.

Which Langflow OSS versions are affected by CVE-2026-79724?

IBM Langflow OSS versions 1.0.0 through 1.11.5 are listed as affected by CVE-2026-79724.

Is there a patch for CVE-2026-79724?

A patch is available from the vendor for CVE-2026-79724; apply the vendor-supplied update or follow their mitigation guidance.

Does CVE-2026-79724 require authentication?

No. CVE-2026-79724 does not require authentication or user interaction to exploit.

References