CVE-2026-12944
IBM Langflow OSS Python Code Injection Allows Root Privilege Escalation and Data Exfiltration.
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
IBM Langflow OSS contains a vulnerability allowing attackers to execute arbitrary Python code as root. This can lead to AWS credential theft, data exfiltration, and lateral movement within internal networks. The vulnerability is reachable via network access to the server.