Langflow unauthenticated RCE (CVE-2026-93674) [PoC]
CVE-2026-93674
CVE-2026-93674: Langflow OSS 1.0.0 to 1.12.2 allows unauthenticated remote code execution (CVSS 9.8). Update to 1.12.3 or later and restrict network access.
Exploitation confirmed - public proof-of-concept - CVE-2026-93674 is a critical OS command injection flaw in IBM Langflow OSS 1.0.0 through 1.12.2 that grants unauthenticated remote code execution. No vendor patch has been confirmed; treat every internet-facing Langflow instance as compromised until upgraded.
Overview
Langflow is an open-source low-code tool for building AI agents and LLM workflows. It accepts user-supplied inputs that are passed to the underlying operating system without proper neutralization of special elements - the classic command injection pattern. Because the vulnerable code path is reachable without authentication, an attacker needs only network access to the service and can run arbitrary commands with the privileges of the Langflow process.
The CVSS score of 9.8 reflects the worst case: attack vector NETWORK, attack complexity LOW, privileges required NONE, and user interaction NONE. In plain terms, there is no gate in front of the bug. A single crafted request can execute shell commands on the host.
Impact
A successful exploit gives the attacker full control over the Langflow server. From there, typical escalation paths include reading environment variables that hold API keys for model providers, exfiltrating workflow data and prompt history, pivoting to other services reachable from the host, and installing persistent backdoors. Langflow deployments often sit inside internal networks with broad access to cloud metadata endpoints, which makes them a high-value first hop for lateral movement.
Remediation
- Check the running version of Langflow. Any release from 1.0.0 through 1.12.2 is affected.
- Upgrade to the latest patched release as soon as IBM publishes it, or to version 1.12.3 or later if available for your distribution.
- If you cannot upgrade immediately, restrict network access to the Langflow web interface. Do not expose it to the public internet. Place it behind an authenticating reverse proxy and allow only trusted source addresses.
- Run Langflow under a low-privilege service account with no access to sensitive credentials or cloud instance metadata.
- Rotate any API keys, database passwords, and tokens that were present in the environment of an exposed instance.
- Review logs for unexpected outbound connections or child processes spawned by the Langflow service.
Security Insight
Command injection in AI tooling is becoming a recurring theme: the same low-code convenience that lets users wire prompts to shell utilities also hands attackers a direct execution path. Langflow’s design decision to expose that path without authentication turns an integration feature into a 9.8. This mirrors the pattern seen across the 2024-2025 wave of RCE bugs in workflow and automation platforms, where the vendor optimized for developer velocity and deferred hardening. Teams running AI infrastructure should treat such tools as hostile-facing services from day one. For related coverage, see our security news and breach reports.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Public PoC References
Unverified third-party code
These repositories are publicly listed on GitHub and have not been audited by Yazoul Security. They may contain malware, backdoors, destructive payloads, or operational security risks (telemetry, exfiltration). Treat them as hostile binaries. Inspect source before execution. Run only in isolated, disposable lab environments (offline VM, no credentials, no production data).
Authorized use only. This information is provided for defensive research, detection engineering, and patch validation. Using exploit code against systems you do not own or do not have explicit written permission to test is illegal in most jurisdictions and violates Yazoul's terms of use.
| Repository | Stars |
|---|---|
| rmhowe425/POC-CVE-2026-93674 POC-CVE-2026-93674 Authenticated Blind command injection proof of concept exploit code | ★ 0 |
Showing 1 of 1 known references. Source: nomi-sec/PoC-in-GitHub.
Related Advisories
Improper Control of Generation of Code ('Code Injection') vulnerability in Themeisle Woody ad snippets insert-php allows Code Injection.This issue affects Woody ad snippets: from n/a through <= 2.7.1....
pdf-image (npm package) through version 2.0.0 allows OS command injection via the pdfFilePath parameter. The constructGetInfoCommand and constructConvertCommandForPage functions use util.format() to i...
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. The username is directly concatenated with the comm...
All versions of the package jsonpath are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. The library relies on the static-eval module to process JS...