CVE-2026-12944: How a Missing Entry in Langflow's Import Blocklist Becomes Root Code Execution
This story is from 2026-09-28. It is preserved in the archive; the latest stories are on the live feed.
At a Glance Item Detail CVE ID CVE-2026-12944 Vulnerability class CWE-918 (SSRF) → authenticated server-side arbitrary code execution CVSS 3.1 9.6 (Critical) — AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N Affected IBM Langflow OSS 1.0.0 – 1.10.0 Fixed in 1.10.1 (1.10.3 if you also want the related auth bug,…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-09-28 00:21 · DEV Community — AI
CVE-2026-12944: How a Missing Entry in Langflow's Import Blocklist Becomes Root Code Execution