What is CVE-2026-8478?
CVE-2026-8478 is a critical vulnerability in IBM Langflow OSS versions 1.0.0 through 1.10.3, caused by improper control of user input code, allowing remote attackers to inject arbitrary code on the system. Affected users should immediately apply patches or discontinue use of impacted versions.
Azərbaycanca: CVE-2026-8478, IBM Langflow OSS-in 1.0.0-dən 1.10.3-ə qədər versiyalarında aşkarlanmış kritik boşluqdur. Bu, uzaqdan hücum edənə sistemə özbaşına kod yeritməyə imkan verən 'improper control of user input code' zəifliyidir. İstifadəçilər dərhal yamaq tətbiq etməli və ya təsirlənmiş versiyaların istifadəsini dayandırmalıdır.
Related CVEs
link basis: same weakness class CWE-94; shared vendor: IBM
FAQ2
Which product versions are affected by CVE-2026-8478?
This vulnerability affects IBM Langflow OSS versions 1.0.0 through 1.10.3.
What type of security vulnerability is CVE-2026-8478 and how can it be exploited?
It is an 'improper control of user input code' vulnerability that allows remote attackers to inject arbitrary code on the affected system.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.