High
Actively Exploited
cisa_kev
·
CVE-2026-9198
IBM Langflow Code Injection Vulnerability
Published Aug 4, 2026
CVSS 9.8
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
Affected AI Products
langflow