← back
CVE-2026-10134criticalCWE-94

Unauthenticated Server-Side RCE via PythonCodeStructuredTool in Public Flows

48Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 10epss 0.6%
from disclosure to weapon66 days
Published on NVDJun 30
1st PoC+66d
exploitation probability
0.6%top 51% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversation, message, file upload, and saved component in the Langflow database, can connect to internal services, abuse cloud metadata endpoints, laterally move to other tenants on the same Langflow instance, and Establish persistence by modifying the public flow's `tool_code` so normal `/api/v1/build/...` calls by any user re-execute attacker code at each build.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
IBM · Langflow OSS
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.