What is CVE-2026-17625?
This CVE describes a vulnerability in IBM Langflow OSS where improper neutralization of special elements could allow a remote authenticated attacker to execute arbitrary commands. Versions 1.0.0 through 1.10.3 are affected, and users should immediately apply the security patches.
Azərbaycanca: Bu CVE, IBM Langflow OSS proqramının istifadəçi tərəfindən daxil edilən məlumatlarda xüsusi elementlərin düzgün neytrallaşdırılmaması səbəbindən uzaqdan autentifikasiya olunmuş təcavüzkarın ixtiyari əmrlər icra etməsinə imkan verən boşluqdur. 1.0.0-dan 1.10.3-ə qədər olan versiyalar təsirə məruz qalır; istifadəçilər dərhal təhlükəsizlik yeniləmələrini tətbiq etməlidirlər.
Related CVEs
link basis: same weakness class CWE-77; shared vendor: IBM
FAQ2
Which product is affected by CVE-2026-17625?
This vulnerability affects IBM Langflow OSS versions 1.0.0 through 1.10.3.
What can an authenticated attacker achieve by exploiting CVE-2026-17625?
A remote authenticated attacker can execute arbitrary commands through this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.