CISA added Langflow to its Known Exploited Vulnerabilities catalog on 2026-08-04, citing CVE-2026-9198, a code...
CISA added Langflow to its Known Exploited Vulnerabilities catalog on 2026-08-04, citing CVE-2026-9198, a code injection flaw allowing unauthenticated remote code execution on default deployments.
confidence score
Strong evidence: 3 independent source classes support this read.
signal brief
CISA added Langflow to its Known Exploited Vulnerabilities catalog on 2026-08-04, citing CVE-2026-9198, a code injection flaw allowing unauthenticated remote code execution on default deployments. This is an urgent signal: federal agencies must patch by 2026-08-07 under BOD 26-04. The advisory references IBM, the current steward of Langflow, and links to an IBM support page.
The same period saw a wave of OSV advisories for Langflow: PYSEC-2026-1521 through 1525 (July 7) cover ReDoS, SSRF, RCE, missing authentication, and exec()-based RCE; PYSEC-2026-2565 through 2569 (July 13) cover API key leak, path traversal, missing ownership check, cleartext auth storage, and injection. These include previously known CVEs (e.g., CVE-2024-9277, CVE-2025-68477) now aggregated in OSV, indicating broad exposure. Separately, a dev release (langflow 1.12.0.dev18) appeared on PyPI on 2026-08-06, but there is no evidence it patches the KEV-listed CVE.
The signal is negative for Langflow's developer trust and enterprise adoption. A known-exploited RCE in a widely used AI workflow tool will force users to apply urgent mitigations or pause deployments, and the cluster of vulnerabilities raises security due-diligence cost. For AI-infra watchers, this is a concrete data point on the security maturity of the AI application layer.
What the sources said:
- CISA: "Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments." (CISA KEV)
- CISA required action: "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 ... guidance." (same source)
- OSV advisory PYSEC-2026-1525: "Langflow affected by Remote Code Execution via validate_code() exec()" (summarized from OSV)
- PyPI lists langflow 1.12.0.dev18 with no patch notes; described only as "A Python package with a built-in web application." (PyPI)
source data used
“CVE: CVE-2026-9198 Vendor/project: IBM Product: Langflow Known ransomware campaign use: Unknown Due date: 2026-08-07 CWE: CWE-94 Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments....”
“A Python package with a built-in web application”
“Aliases: CVE-2024-9277, GHSA-355v-2rjx-fpx7 Inefficient Regular Expression Complexity in langflow”
“Aliases: CVE-2025-68477, GHSA-5993-7p27-66g5 Langflow vulnerable to Server-Side Request Forgery”
“Aliases: CVE-2024-48061, GHSA-5p5r-57fx-pmfr Langflow vulnerable to remote code execution”
“Aliases: CVE-2026-21445, GHSA-c5cp-vx83-jhqx, PYSEC-2026-2571 Langflow Missing Authentication on Critical API Endpoints”
“Aliases: CVE-2026-0770, GHSA-g22f-v6f7-2hrh Langflow affected by Remote Code Execution via validate_code() exec()”
“Aliases: CVE-2026-6597, GHSA-5jjf-wcvf-923w Langflow has an Information Leak through Incomplete API Key Redaction”
“Aliases: CVE-2026-42867, GHSA-79ph-745m-6wxq Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint”
“Aliases: CVE-2026-34046, GHSA-8c4j-f57c-35cf, PYSEC-2026-2570 Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check”
“Aliases: CVE-2026-6598, GHSA-9jpj-cph8-w449 Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint”
“Aliases: CVE-2026-6599, GHSA-v66p-f7x3-4794 Langflow vulnerable to injection”
Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.