What is CVE-2026-17632?
CVE-2026-17632: In IBM Langflow OSS 1.0.0 through 1.10.3, improper Python code validation during AST-based security scanning could allow a remote authenticated attacker to execute arbitrary code. Affected users should update to a patched version or strengthen input validation mechanisms immediately.
Azərbaycanca: CVE-2026-17632: IBM Langflow OSS 1.0.0-1.10.3 versiyalarında autentifikasiya olunmuş uzaqdan hücumçuya, AST əsaslı skan zamanı Python kodunun düzgün yoxlanılmaması səbəbindən ixtiyari kod icrasına imkan verən boşluqdur. İstifadəçilər dərhal yamalanmış versiyaya keçməli və ya giriş təsdiqləmə mexanizmlərini gücləndirməlidir.
Related CVEs
link basis: same weakness class CWE-94; shared vendor: IBM
FAQ2
Is authentication required for an attacker to exploit CVE-2026-17632?
Yes, the vulnerability requires the attacker to be authenticated. It allows a remote authenticated attacker to execute arbitrary code.
Which versions of IBM Langflow OSS are affected by CVE-2026-17632?
This vulnerability affects IBM Langflow OSS versions 1.0.0 through 1.10.3. Users should immediately update to a patched version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.