CVE-2026-7524: Langflow
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links during archive extraction.
Affected products
- Langflow Langflow: from 1.0.0, up to and including 1.9.1
Published 2026-05-27. Last modified 2026-06-17.