SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-81940

HIGH · CVSS 8.8 EPSS 0.54%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

IBM Langflow OSS versions 1.0.0 to 1.11.5 are vulnerable to arbitrary code execution due to improper handling of special characters in flow display names, allowing remote authenticated attackers to exploit this flaw. Organizations using these versions should prioritize patching this vulnerability to mitigate the risk of unauthorized code execution and potential system compromise. Immediate action is recommended for users managing sensitive data or critical applications within their environments.

CVE
CVE-2026-81940
Severity
HIGH
CVSS
8.8
EPSS
0.54%

Original NVD Description

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names.