What is CVE-2026-17623?
CVE-2026-17623 is a critical vulnerability in IBM Langflow OSS versions 1.0.0 through 1.10.3, allowing a remote authenticated attacker to execute arbitrary commands due to improper validation of the `command` field in MCP server configurations. Affected users should immediately upgrade to a patched version and review their MCP server configurations.
Azərbaycanca: CVE-2026-17623, IBM Langflow OSS-in 1.0.0-dən 1.10.3-ə qədər versiyalarına təsir edən, autentifikasiya olunmuş uzaqdan hücumçuya MCP server konfiqurasiyasındakı `command` sahəsinin düzgün yoxlanılmaması səbəbilə ixtiyari əmrlər icra etməyə imkan verən kritik boşluqdur. Təsirə məruz qalan sistemlərdə istifadəçilər təcili olaraq yamaqlanmış versiyaya yenilənməli və MCP server konfiqurasiyalarını nəzərdən keçirməlidir.
Related CVEs
link basis: same weakness class CWE-77; shared vendor: IBM
FAQ2
Which versions of IBM Langflow OSS are affected by CVE-2026-17623?
This vulnerability affects IBM Langflow OSS versions 1.0.0 through 1.10.3.
Does exploiting CVE-2026-17623 require authentication?
Yes, the vulnerability allows a remote authenticated attacker to execute arbitrary commands in the `command` field of MCP server configurations.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.