AINewsnow

CVE-2026-12944: How a Missing Entry in Langflow's Import Blocklist Becomes Root Code Execution

This story is from 2026-09-28. It is preserved in the archive; the latest stories are on the live feed.

At a Glance Item Detail CVE ID CVE-2026-12944 Vulnerability class CWE-918 (SSRF) → authenticated server-side arbitrary code execution CVSS 3.1 9.6 (Critical) — AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N Affected IBM Langflow OSS 1.0.0 – 1.10.0 Fixed in 1.10.1 (1.10.3 if you also want the related auth bug,…

Read the full story at DEV Community — AI ↗

Timeline · 1 report

  1. 2026-09-28 00:21 · DEV Community — AI
    CVE-2026-12944: How a Missing Entry in Langflow's Import Blocklist Becomes Root Code Execution

More stories

  1. Scoop: Anthropic's Dario Amodei to have White House dinner with Trump — Axios AI+
  2. Bill Gates says unchecked AI could ‘cause a billion deaths’ in call for regulation — The Guardian AI
  3. Unsecured OpenAI agents posted 53 user images on the internet without the lab's knowledge — TechCrunch AI
  4. Scoop: Top AI companies probing tens of thousands of security incidents — Axios AI+
  5. OpenAI’s A.I. Went Rogue and Meddled With U.S. Government Websites — New York Times Technology
  6. The Surprising Reasons China Is Skeptical of A.I. Safety Calls — New York Times AI
  7. Did anyone do a full bench of e.g. Qwen Flash Next IQ4 and Qwen 27b FP8? Here are some — r/LocalLLaMA
  8. ‘Things Will Never Be Chill Again’: The Doomers Who Shaped the AI Safety Freakout — Wall Street Journal Technology

Get the daily brief of stories like this at 6:30 every morning →