[Module-request] CVE-2026-9198 (RCE in Langflow)
Open
@Franc-Zar is already working on this.
Since Aug 8, 2026.
- Dominant language
- Python
- Stars
- 5.6k
- Forks
- 1.2k
- Avg merge
- 1d 21h
- Merged PRs (30d)
- 16
Description
Description
CVE-2026-9198 is a critical code injection vulnerability (CVSS score 9.8) in IBM Langflow OSS versions 1.0.0 through 1.10.0. It allows unauthenticated network attackers to achieve full remote code execution on default deployments by chaining two unsecure API endpoints to generate superuser tokens and run arbitrary code.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.