Twenty-Five Flaws, Two No-Login RCEs — IBM’s Langflow 1.12.3 Batch and the Credential Store Behind It
IBM published a security bulletin on 2 October 2026 covering 25 vulnerabilities in Langflow OSS, versions 1.0.0 through 1.12.2, with the fix in 1.12.3. Two of the 25 score CVSS 3.1 9.8 and need neither login nor user interaction: CVE-2026-104334, described as improper control of code generation, and CVE-2026-93674, improper neutralization of special elements in an OS command. Both are unauthenticated remote code execution. The rest of the batch breaks down as 19 high and 4 medium severity, and 15 of the 25 can lead to code execution. No in-the-wild exploitation has been reported and no public proof-of-concept has been confirmed — which, given Langflow’s year, reads less like reassurance and more like a short grace period.
This is the same product that entered the CISA KEV catalog as the first AI agent platform, that we tracked through CVE-2026-0768’s code-validator RCE still being harvested in October, and that shipped two 9.9 MCP-stdio advisories disagreeing about their own fixed version. A 25-flaw bulletin is not an anomaly for Langflow in 2026. It is the cadence.
The two 9.8s and the near-miss third
CVE-2026-104334 and CVE-2026-93674 are the pair that matters to anyone with Langflow reachable on a network: no credentials, no victim click, code execution. A third flaw, CVE-2026-93675 (CVSS 8.8), abuses dependency confusion and likewise needs no login, though it does require a user to take an action — the classic download-and-point-the-loader shape, where the attacker’s leverage is naming rather than access.
The interesting engineering detail is that the two criticals are different bugs with the same blast radius. One sits in code generation control, the other in OS-command neutralization. That means they are unlikely to share a single choke point a defender could gate once at the proxy. Until 1.12.3 is installed, there is no one rule that covers both — which is the practical argument for treating the bulletin as a single upgrade event rather than triaging 25 CVEs individually.
The authenticated half is a sandbox-escape catalogue
Most of the remaining flaws require an account, but “requires an account” on a platform whose Python components are the product means something weaker than it sounds. CVE-2026-97655 slips past what the bulletin calls an incomplete blocklist in the code security scanner; CVE-2026-97676 is a straight sandbox escape. CVE-2026-93447 abuses deserialization of cached Redis values, though it demands both the server secret and Redis write access — a meaningful bar. CVE-2026-97677 lets a flow author write files into any directory the service account can write and read back configuration files, secrets, or database files. And CVE-2026-93679 crashes the server with oversized ZIP archives, the denial-of-service footnote in a batch otherwise about execution.
The blocklist-bypass entry deserves a pause. A scanner that rejects known-dangerous constructs is a denylist standing in front of a Turing-complete language, and CVE-2026-97655 is what that bet looks like when it loses. Every Langflow bulletin this year has contained at least one “the guard did not cover this path” flaw; defenders should treat flow-author privileges as code execution until proven otherwise, on every version, regardless of what the scanner claims.
The credential store is the real prize
Surfacing in the same window, GitHub carries GHSA-jxw3-mjmx-3pqm, “Weak Fernet Key via random.seed()” (CVSS 9.1): Langflow derives the Fernet key protecting all stored user credentials — API keys, LLM provider secrets, database passwords — from Python’s Mersenne Twister PRNG seeded with SECRET_KEY. When that secret is shorter than 32 characters, the routine self-hosted case, the derived key is fully deterministic and reproducible offline by anyone holding the seed. And even in the “safe” 32-plus branch, the raw key material is used directly as the Fernet key, so exfiltrating the secret file alone decrypts everything with no further computation.
Read that alongside CVE-2026-97677’s arbitrary file read and the unauthenticated RCE pair, and the batch composes into something worse than its parts: the execution flaws get you in, the traversal flaw gets you the secret, and the Fernet weakness turns the secret into every credential the platform holds. Langflow servers concentrate exactly the material — model API keys, database credentials, provider secrets — that survives the compromise of any single host. That is why the bulletin’s device matters less than its blast radius, and why rotation of everything Langflow ever stored belongs in the upgrade runbook, not after it.
What to do
- Upgrade to 1.12.3 now. One release clears all 25, including both unauthenticated 9.8s. Until then, keep Langflow off the public internet — the two criticals need nothing but network reachability.
- Rotate everything Langflow stored. API keys, LLM provider secrets, database passwords, OAuth grants. The Fernet key-derivation weakness means a past file read may already have decided this for you.
- Restrict who can author flows. Most of the batch needs an account, and the scanner bypass plus sandbox escape mean flow authorship is effectively execution. Least privilege on flow creation is a preventive control, not housekeeping.
- Do not wait for NVD. None of the three headline CVEs had been ingested into NVD at the time of writing. Scanner coverage that keys off NVD publication will lag this batch by days; the IBM bulletin and the 1.12.3 tag are the signals that exist today.
- Hunt, don’t just patch. No exploitation has been reported, but Langflow RCEs have a documented harvest-then-exploit pipeline this year. Check for unexpected flows, outbound connections from the Langflow host, and reads against the secret store before declaring the upgrade sufficient.
Verification note: CVE IDs, CVSS scores, weakness classes, the 1.0.0–1.12.2 affected range, the 1.12.3 fix version, the severity split (2 critical / 19 high / 4 medium), the “15 lead to code execution” count, and the no-exploitation / no-confirmed-PoC status come from contemporaneous reporting of IBM’s 2 October bulletin across three independent outlets (5–6 October 2026). We queried the NVD CVE 2.0 API on 6 October: CVE-2026-104334, CVE-2026-93674 and CVE-2026-93675 had not been ingested. The Fernet key-derivation details and its 9.1 score were read directly from the GitHub repository advisory API record for GHSA-jxw3-mjmx-3pqm. We ran no exploit, tested no deployment, and did not contact IBM before publication.
Sources:
- SecurityOnline — IBM Patches 25 Langflow Vulnerabilities, Including Two Critical Remote Code Execution Flaws (6 October 2026)
- CyberPress — IBM Patches Critical Langflow Vulnerabilities Enabling Remote Code Execution (5 October 2026)
- GBHackers — IBM Patches Multiple Langflow OSS Flaws Including Two Critical RCE Vulnerabilities (6 October 2026)
- GHSA-jxw3-mjmx-3pqm — Weak Fernet Key via random.seed() (CVSS 9.1; verified via the GitHub advisory API)
- GitLab Advisory Database — CVE-2026-9205 / GHSA-jxw3-mjmx-3pqm (references IBM support bulletin node/7282648)