Agents
IBM discloses three high-severity Langflow CVEs, including authenticated RCE via path traversal and API keys that outlive user deactivation
GitHub advisories published 2026-09-11 list CVE-2026-84889 (CVSS 8.8, path-traversal RCE, Langflow 1.0.0 to 1.10.3), CVE-2026-81213 (CVSS 8.6, SSRF into internal networks, through 1.11.5) and CVE-2026-81268 (CVSS 8.1). The third lets a deactivated user's API keys keep executing flows. IBM published a support bulletin for each. Self-hosted Langflow deployments on anything older than 1.11.5 should upgrade and rotate API keys belonging to offboarded users.
↳ Follow the thread