Vulnerability Intelligence Report
Unauthenticated Server-Side RCE via PythonCodeStructuredTool in Public Flows
CVE-2026-10134
IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversation, message, file upload, and saved component in the Langflow database, can connect to internal services, abuse cloud metadata endpoints, laterally move to other tenants on the same Langflow instance, and Establish persistence by modifying the public flow's `tool_code` so normal `/api/v1/build/...` calls by any user re-execute attacker code at each build.
No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
EPSS Probability:0.31%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-94 ↗CWE-94 Improper Control of Generation of Code ('Code Injection')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| IBM | Langflow OSS | 1.0.0 <= 1.9.3 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.314%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | IBM Corporation · Vendor · USA |
| Reserved | 2026-05-29T18:38:25 |
| Published | 2026-06-30T19:56:52 |
| Last Updated | 2026-07-01T17:27:28 |
Community Chatter & Buzz