External risk intelligence

IBM Langflow OSS Remote Code Execution via Dependency Confusion

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-93675

Langflow is a web-based user interface and platform designed for building AI workflows and applications. These tools are typically deployed as web applications accessible over the network to facilitate collaborative development and service orchestration, making them a common target for public or internal network exposure as part of an edge or development service environment.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a critical vulnerability found in certain versions of IBM's Langflow OSS, a platform used for building AI workflows. The issue stems from an unexpected dependency confusion, which could allow an unauthorized remote attacker to execute arbitrary code on affected systems. The primary concern is confirming if our environment utilizes these specific versions of Langflow OSS, as the potential for code execution is significant.

  • Unchecked code execution risk in AI workflow tools.
  • Affects systems building AI applications and workflows.
  • Confirm relevance; no immediate action if not in use.

Attack Path

How an attacker could exploit the issue

An attacker could exploit a dependency confusion vulnerability in IBM Langflow OSS by tricking the system into using a malicious package instead of a legitimate one. This could allow them to execute arbitrary code on the targeted system.

  • An attacker can reach the vulnerability remotely.
  • The vulnerability is triggered by a dependency confusion.
  • The risk is arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow a remote attacker to execute arbitrary code on systems running IBM Langflow OSS when a specific dependency is not properly managed. This could impact the integrity and availability of the affected service.

  • System data could be compromised.
  • Dependency confusion may cause execution.
  • Arbitrary code execution is possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in IBM Langflow OSS affects organizations using the platform for AI workflow development. Given its nature as a web-based application often deployed for collaborative development or service orchestration, the platform and infrastructure teams are likely responsible for its upkeep. The immediate first step is to confirm the presence and reachability of Langflow instances, identify their business criticality, and locate the accountable owner to prioritize remediation efforts.

  • Platform and infrastructure teams own resolution.
  • Verify Langflow instances and their reachability.
  • Plan remediation based on confirmed exposure.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is IBM Langflow OSS?

Langflow is a web-based, low-code platform specifically designed for building and managing AI workflows and applications. It acts as an orchestration engine, allowing users to visually assemble complex AI models and data pipelines. Because it facilitates collaborative development, it is frequently deployed as a network-accessible service within corporate environments or development workflows.

How does CVE-2026-93675 work?

This vulnerability is classified as CWE-440, which involves an unexpected dependency confusion. In practice, this means the software can be manipulated into pulling a malicious, untrusted software package instead of the legitimate, intended library. By successfully tricking the system into using this rogue package, an attacker can gain the ability to execute arbitrary code on the underlying server.

What triggers this remote code execution?

The vulnerability is triggered when the application fails to verify the authenticity of a dependency during the software's build or runtime processes. It is important to note that simply visiting the web interface does not inherently trigger this flaw; rather, it requires a specific environment configuration where the system can be coerced into resolving and loading external, malicious code instead of the correct components.

Why should I care about this vulnerability?

If you are running an instance of Langflow, you should be concerned because the flaw allows for remote, unauthenticated access. According to Halo Surface Signal, these platforms are often deployed as web applications accessible over a network to support collaboration. If your instance is reachable via a network, the potential for an attacker to compromise your system or data is significantly elevated.

What should I do if I use Langflow?

Your first step is to perform an inventory of your environment to confirm if you are running any version of Langflow OSS between 1.0.0 and 1.12.2. If you find an affected instance, determine its role and whether it is accessible from your network. Once identified, work with your infrastructure or platform engineering teams to plan for an upgrade to version 1.12.3 or later, which resolves the dependency management issue.

References