IBM has issued a security bulletin detailing 25 vulnerabilities in Langflow OSS, spanning versions 1.0.0 to 1.12.2. Of these, two are rated critical and allow unauthenticated remote code execution: CVE-2026-104334, arising from improper control of code generation, and CVE-2026-93674, due to improper neutralisation of special elements used in OS commands. A third flaw, CVE-2026-93675 (CVSS 8.8), also enables unauthenticated access via dependency confusion, though it requires a user action.
IBM notes that 15 of the flaws could lead to code execution, with many targeting authenticated users through bypasses of the platform’s code security checks. There is no public confirmation of an active exploit in the wild in the bulletin.
IBM recommends upgrading to Langflow 1.12.3 as the immediate mitigation. In the meantime, organisations should keep Langflow off the public internet and restrict who can create or edit flows, since most vulnerabilities require an account. After patching, credentials and API keys stored within the platform should be rotated. The bulletin emphasises that Langflow servers often hold API keys, database credentials and model secrets, meaning a compromise could expose far more than the Langflow host itself.
The article notes that there is no public PoC confirmed for these flaws, and emphasises upgrading as the primary preventative measure.