Why code execution in an LLM orchestrator carries more weight than its CVSS score
Vulnerability overview
Three Langflow OSS vulnerabilities fixed by IBM carry CVSS v3 scores of 9.8. They are CVE-2026-79724, CVE-2026-85025 and CVE-2026-81204. The Dutch NCSC documented them in advisory NCSC-2026-0392 on 23 September 2026 and states they can be exploited remotely without authentication and without user interaction.
Mechanism and exploitation conditions
The advisory places the Langflow issues in the code injection and OS command injection families. Each of these weaknesses means the same thing in practice. Unvalidated input reaches an interpreter. On a platform whose entire purpose is to run code that a user configures, the boundary between intended execution and injected execution is thin. That is why the advisory also lists missing and incorrect authorization alongside the injection classes for the full set of 12 CVEs.
Impact
A nine point something score already signals severity. Operational context raises it further. Orchestration platforms concentrate trust. They hold provider API keys, they hold connectors to internal data stores, and they run tool code with database and network reach. Code execution here is not a single tenant loss. It is a stepping stone into everything the platform was given access to.
Affected products and scope
The advisory names Langflow OSS, IBM MQ and IBM MQ Appliance. It does not publish vulnerable version ranges or fixed builds, pointing instead to the IBM bulletins for the fixes. Any deployment that accepts untrusted input should be treated as in scope until proven patched.
Exposure context
A ZoomEye query for app="Langflow" returned 18,550 matching instances when checked on 23 September 2026. That is a product fingerprint count, not a vulnerability confirmation.
Remediation and mitigations
Apply the IBM updates, and treat the platform as a privileged system in its own right. Place it behind authentication, restrict who can deploy flows, and give it the least credentials the business case allows. After patching, audit the keys and tokens it could previously read and rotate them if there is any sign of tampering.
References
- NCSC-NL, advisory NCSC-2026-0392 (23 September 2026): https://advisories.ncsc.nl/advisory?id=NCSC-2026-0392
- IBM security bulletin for the Langflow OSS fixes: https://www.ibm.com/support/pages/node/7284543
- IBM security bulletin for the IBM MQ fixes: https://www.ibm.com/support/pages/node/7286666
Top comments (0)