A critical vulnerability in IBM’s Langflow, a low-code AI builder, has been identified, allowing unauthenticated attackers to execute code remotely on default deployments. The Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability, designated as CVE-2026-9198, to its Known Exploited Vulnerabilities catalog due to evidence of active exploitation.
Details of the Vulnerability
The flaw affects Langflow OSS versions 1.0.0 through 1.10.0. IBM recommends that organizations upgrade to version 1.10.1 or later, with the latest version being 1.11.2 at the time of reporting. The vulnerability arises from two issues in default deployments: an auto-login endpoint that can generate superuser tokens for any network caller and a code validation endpoint that executes any Python code sent to it.
Potential Impact on Organizations
This combination of vulnerabilities poses a significant risk, as it allows attackers to gain superuser rights and execute arbitrary code, potentially compromising entire Langflow servers. The flaw’s critical nature means that organizations using default configurations are particularly vulnerable.
Current Exploitation Status
While the CVE was published on July 17, it remains unclear how extensively this vulnerability has been exploited in the wild. IBM has been contacted for further information regarding the scope of the attacks.
Background on Langflow
Langflow is designed to facilitate the creation of agent workflows without requiring extensive coding knowledge. Originally developed by Logspace and later acquired by DataStax in 2024, it became part of IBM’s offerings when IBM acquired DataStax in 2025. Despite its user-friendly interface, the platform’s default configurations have led to this critical security issue.
This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.
Original source: theregister.com








