CVE-2026-8635
קריטית 9.9
תיאור (מקור, אנגלית)
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve full system compromise with Langflow service permissions.
מדדים
- CVSS 3.1
-
9.9 (CRITICAL)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-3/8/2026
- CWE
- CWE-94
מוצרים מושפעים
langflow: langflow; apple: macos; linux: linux kernel; microsoft: windows
קישורים
- https://www.ibm.com/support/pages/node/7278925 Vendor Advisory