CVE-2026-9196: IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to improper handling of LLM‑generated components. The ...
Added to the CISA Known Exploited Vulnerabilities catalog on 05 Aug 2026. Vendor: AI/ML. Product: LLM. CVSS score: 8.1.
IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to improper handling of LLM‑generated components. The application executes model‑generated Python code in the backend during validation prior to user appr...
Required action: Review and patch if applicable to your AI infrastructure.