Beyond the Badge: Why Authenticated Langflow Users Still Escape the Sandbox
IBM has published a security bulletin covering 25 vulnerabilities in Langflow OSS versions 1.0.0 through 1.12.2. Two are critical and need no login, but the bulk of the batch targets users who already hold an account.
Vulnerability Overview
It is tempting to treat authenticated flaws as lower priority. In a workflow platform, an account is the expected starting point, not a barrier. Langflow lets a flow author define executable logic, so a weakness in the code security layer converts a legitimate author into a server-level actor.
Mechanism and Exploitation Conditions
Scanner Bypass
CVE-2026-97655 slips past an incomplete blocklist in the code security scanner. Blocklists fail by omission: a construct that the list does not name passes through unchanged.
Sandbox Escape
CVE-2026-97676 enables a sandbox escape. The sandbox exists to contain flow code, so its defeat removes the last boundary between user-supplied logic and the host process.
Deserialization of Cached Values
CVE-2026-93447 abuses deserialization of cached Redis values, but it requires the server secret and Redis write access. That precondition matters for triage: not every authenticated flaw is equally reachable.
The Unauthenticated Counterpart
CVE-2026-104334 stems from improper control of code generation and CVE-2026-93674 involves improper neutralization of special elements used in an OS command. Both need no login and no user interaction, so an exposed instance fails first and fastest.
Impact
A sandbox escape means code runs with the privileges of the Langflow service account. On typical deployments that account can reach stored credentials, internal model endpoints and configuration files, turning a single malicious flow into a platform compromise.
Affected Products and Scope
All 25 flaws affect Langflow OSS 1.0.0 through 1.12.2. IBM's advisory does not report exploitation in the wild, and no public proof-of-concept has been confirmed. Of the 25 flaws, 2 are critical, 19 are high and 4 are medium, and 15 of these flaws can lead to code execution. CVE-2026-93675, which carries a CVSS score of 8.8, abuses dependency confusion and needs no login, although a user must take an action for it to be triggered.
Remediation and Mitigations
Upgrade to Langflow 1.12.3. IBM strongly recommends addressing the vulnerability now. Until the upgrade is done, keep Langflow off the public internet. Limit who can create or edit flows. After patching, rotate any API keys and credentials that are stored in the platform.
Top comments (0)