🚨SEVERITY: CRITICAL — CVSS 9.8Security Advisory
TL;DR 📌
- Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
- Highest CVSS: 9.8 (Critical).
- Listed in CISA KEV (2026-08-04) — this is being exploited in the wild.
- Check the advisory for fixed releases — remediation detail is in the vendor link below.
- CVEs: CVE-2026-9198.
What it is
CVE-2026-9198 is a code injection vulnerability in IBM Langflow. It allows an unauthenticated attacker to achieve full remote code execution on a default Langflow deployment.