What is CVE-2026-9196?
A vulnerability in IBM Langflow OSS versions 1.0.0 through 1.10.3 allows an authenticated attacker to execute unintended Python code in the backend during Agentic Assistant validation. This occurs due to improper handling of LLM-generated components before user approval.
Azərbaycanca: IBM Langflow OSS-in 1.0.0-dən 1.10.3-ə qədər versiyalarında autentifikasiya olunmuş hücumçuya LLM tərəfindən yaradılan Agentic Assistant komponentlərinin yoxlanması zamanı arxa planda Python kodunu icra etməyə imkan verən boşluq aşkarlanıb. Bu, istifadəçi təsdiqləmədən əvvəl baş verdiyi üçün zərərli kod icrası ilə nəticələnə bilər.
Related CVEs
link basis: same weakness class CWE-94; shared vendor: IBM
FAQ2
Which versions of IBM Langflow OSS are vulnerable to CVE-2026-9196?
IBM Langflow OSS versions 1.0.0 through 1.10.3 are affected by this vulnerability.
What can an attacker execute in the backend by exploiting CVE-2026-9196?
An authenticated attacker can execute unintended Python code in the backend during Agentic Assistant validation of LLM-generated components.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.