What is CVE-2026-17624?
A critical vulnerability in IBM Langflow OSS versions 1.0.0 through 1.10.3 allows remote authenticated attackers to execute arbitrary code due to improper validation of module imports. Affected systems should immediately apply security patches and restrict module import logic.
Azərbaycanca: IBM Langflow OSS-in 1.0.0-dan 1.10.3-ə qədər olan versiyalarında modul idxallarının düzgün yoxlanılmaması səbəbindən uzaqdan autentifikasiya olunmuş hücumçuya ixtiyari kod icrasına imkan verən kritik boşluq aşkar edilib. Təsirə məruz qalan sistemlərdə dərhal təhlükəsizlik yeniləmələri tətbiq edilməli və modul idxalı məntiqi məhdudlaşdırılmalıdır.
Related CVEs
link basis: same weakness class CWE-94; shared vendor: IBM
FAQ2
Which product is affected by CVE-2026-17624 and what is the cause?
This vulnerability affects IBM Langflow OSS. The cause is improper validation of module imports in versions 1.0.0 through 1.10.3.
What level of access does an attacker need to exploit CVE-2026-17624?
The attacker must be a remote authenticated user to exploit this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.