← לוח פגיעויות

CVE-2026-8481

קריטית 9.9

תיאור (מקור, אנגלית)

IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts user-supplied Python code and executes it directly using Python's built-in exec() function without sandboxing, input validation, or privilege restrictions, enabling any authenticated user to execute arbitrary system commands with the full privileges of the Langflow server process.

מדדים

CVSS 3.1
9.9 (CRITICAL) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-3/8/2026
CWE
CWE-94

מוצרים מושפעים

langflow: langflow; apple: macos; linux: linux kernel; microsoft: windows

קישורים