Critical 9.8

Langflow unauthenticated RCE (CVE-2026-93674) [PoC]

CVE-2026-93674

By Yazoul AI · automated

CVE-2026-93674: Langflow OSS 1.0.0 to 1.12.2 allows unauthenticated remote code execution (CVSS 9.8). Update to 1.12.3 or later and restrict network access.

Exploitation confirmed - public proof-of-concept - CVE-2026-93674 is a critical OS command injection flaw in IBM Langflow OSS 1.0.0 through 1.12.2 that grants unauthenticated remote code execution. No vendor patch has been confirmed; treat every internet-facing Langflow instance as compromised until upgraded.

Overview

Langflow is an open-source low-code tool for building AI agents and LLM workflows. It accepts user-supplied inputs that are passed to the underlying operating system without proper neutralization of special elements - the classic command injection pattern. Because the vulnerable code path is reachable without authentication, an attacker needs only network access to the service and can run arbitrary commands with the privileges of the Langflow process.

The CVSS score of 9.8 reflects the worst case: attack vector NETWORK, attack complexity LOW, privileges required NONE, and user interaction NONE. In plain terms, there is no gate in front of the bug. A single crafted request can execute shell commands on the host.

Impact

A successful exploit gives the attacker full control over the Langflow server. From there, typical escalation paths include reading environment variables that hold API keys for model providers, exfiltrating workflow data and prompt history, pivoting to other services reachable from the host, and installing persistent backdoors. Langflow deployments often sit inside internal networks with broad access to cloud metadata endpoints, which makes them a high-value first hop for lateral movement.

Remediation

  • Check the running version of Langflow. Any release from 1.0.0 through 1.12.2 is affected.
  • Upgrade to the latest patched release as soon as IBM publishes it, or to version 1.12.3 or later if available for your distribution.
  • If you cannot upgrade immediately, restrict network access to the Langflow web interface. Do not expose it to the public internet. Place it behind an authenticating reverse proxy and allow only trusted source addresses.
  • Run Langflow under a low-privilege service account with no access to sensitive credentials or cloud instance metadata.
  • Rotate any API keys, database passwords, and tokens that were present in the environment of an exposed instance.
  • Review logs for unexpected outbound connections or child processes spawned by the Langflow service.

Security Insight

Command injection in AI tooling is becoming a recurring theme: the same low-code convenience that lets users wire prompts to shell utilities also hands attackers a direct execution path. Langflow’s design decision to expose that path without authentication turns an integration feature into a 9.8. This mirrors the pattern seen across the 2024-2025 wave of RCE bugs in workflow and automation platforms, where the vendor optimized for developer velocity and deferred hardening. Teams running AI infrastructure should treat such tools as hostile-facing services from day one. For related coverage, see our security news and breach reports.

Further Reading

Share:

Never miss a critical vulnerability

Get real-time security alerts delivered to your preferred platform.

Public PoC References

Unverified third-party code

These repositories are publicly listed on GitHub and have not been audited by Yazoul Security. They may contain malware, backdoors, destructive payloads, or operational security risks (telemetry, exfiltration). Treat them as hostile binaries. Inspect source before execution. Run only in isolated, disposable lab environments (offline VM, no credentials, no production data).

Authorized use only. This information is provided for defensive research, detection engineering, and patch validation. Using exploit code against systems you do not own or do not have explicit written permission to test is illegal in most jurisdictions and violates Yazoul's terms of use.

Repository Stars
rmhowe425/POC-CVE-2026-93674

POC-CVE-2026-93674 Authenticated Blind command injection proof of concept exploit code

★ 0

Showing 1 of 1 known references. Source: nomi-sec/PoC-in-GitHub.

Related Advisories

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.