CVE-2026-17632·Python vulnerability
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code during AST-based security scanning.
- Severity
- high
- Software
- Python
- Fixed in
- 1.11.0
- Published
- 2026-08-05
Affected versions
From: 1.0.0
Until: 1.11.0
Fixed in: 1.11.0
How to fix this CVE
Update IBM Langflow OSS to version 1.11.0 or later to remediate the arbitrary code execution vulnerability caused by insufficient AST validation in Python code processing. Organizations running versions 1.0.0 through 1.10.3 should prioritize this update immediately, as authenticated attackers could bypass security controls and execute malicious code within the Langflow environment.
sudo dnf update python3 -y && pip3 install --upgrade langflow==1.11.0Defensia detects this vulnerability
How to check if you are affected
- Check installed Langflow version: pip3 show langflow | grep Version
- Verify Python version and installed packages: python3 --version && pip3 list | grep -i langflow
- Review Langflow application logs for AST parsing errors or unexpected code execution: grep -i 'ast\|parse\|execute' /var/log/langflow/*.log /var/log/application/*.log 2>/dev/null
- Confirm the update was applied: pip3 show langflow | grep Version (should display 1.11.0 or higher)
FAQ
What is CVE-2026-17632?
This vulnerability affects IBM Langflow OSS where improper validation of Python code during Abstract Syntax Tree (AST) scanning allows authenticated users to bypass security restrictions and execute arbitrary Python code on the server.
Is CVE-2026-17632 being actively exploited?
No, this vulnerability is not currently listed on the CISA KEV catalog and has no known public exploits available, though it remains a critical security risk due to its high CVSS score of 8.8.
What versions of IBM Langflow OSS are affected by CVE-2026-17632?
Versions 1.0.0 through 1.10.3 are vulnerable. Version 1.11.0 and later contain the security patch.
How do I check if my server is vulnerable to CVE-2026-17632?
Run 'pip3 show langflow | grep Version' to check your installed version. If it shows 1.10.3 or earlier, your installation is vulnerable.
Does Defensia detect CVE-2026-17632?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Langflow is installed on a monitored server, CVE-2026-17632 will appear in your dashboard with remediation steps.
Related Python CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-17632. Free for 1 server.
Get started free