DIRAS TAKE
Urgent: this is a remote, unauthenticated command injection with critical impact (CVSS 9.8); prioritize isolating internet-facing Langflow OSS instances and apply vendor fixes or mitigations immediately.
What is CVE-2026-79724?
An unauthenticated remote attacker can execute arbitrary operating system commands on IBM Langflow OSS, resulting in full confidentiality, integrity, and availability impact (CVE-2026-79724). The flaw is a command injection (CWE-78) that affects Langflow OSS versions 1.0.0 through 1.11.5; an attacker only needs network access to a vulnerable Langflow OSS instance to exploit it because no privileges or user interaction are required. The weakness is classified as CWE-78 (OS Command Injection).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of IBM Langflow OSS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 1.x | 1.0.0 – 1.11.5 |
Is CVE-2026-79724 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-79724
- Apply the vendor-provided patch or guidance immediately (vendor has indicated a patch is available).
- If a fixed package is not yet deployed, restrict network access to Langflow OSS instances to trusted hosts only.
- Monitor application and host logs for suspicious command execution and anomalous process activity.
- Follow vendor guidance for configuration changes or temporary mitigations until patched.
Frequently asked questions
Is CVE-2026-79724 being actively exploited?
There are no public reports of exploitation of CVE-2026-79724 as of 2026-09-29.
Which Langflow OSS versions are affected by CVE-2026-79724?
IBM Langflow OSS versions 1.0.0 through 1.11.5 are listed as affected by CVE-2026-79724.
Is there a patch for CVE-2026-79724?
A patch is available from the vendor for CVE-2026-79724; apply the vendor-supplied update or follow their mitigation guidance.
Does CVE-2026-79724 require authentication?
No. CVE-2026-79724 does not require authentication or user interaction to exploit.
References
- nvd.nist.gov/vuln/detail/CVE-2026-79724
- cve.org/CVERecord?id=CVE-2026-79724
- ibm.com/support/pages/node/7286666
- All IBM CVEs on CVE Radar
- CVEs published in September 2026