CVE-2026-7803: Langflow
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validation of flow nodes with missing or empty component type fields.
Affected products
- Langflow Langflow: from 1.0.0, up to and including 1.10.0
Published 2026-06-30. Last modified 2026-07-02.