CVE-2026-9198: IBM Langflow's Unauthenticated Remote Code Execution Chain
Technical root cause and active exploitation details for the CVSS 9.8 unauthenticated remote code execution flaw in IBM Langflow.
An unauthenticated remote code execution chain in IBM Langflow—a popular visual framework for building AI and LLM agents—is under active exploitation, allowing remote attackers to achieve arbitrary code execution inside AI deployment pipelines.
CVE-2026-9198 (CWE-94: Code Injection)
Severity & CVSS: Critical 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Exploitation Status: ⚠️ Actively Exploited in the Wild
Affected Versions: Langflow prior to patched releases
What's Affected
Langflow instances exposed to untrusted networks without strict authentication layers enabled. Because Langflow serves as an orchestration engine integrating vector stores, model weights, API keys, and enterprise databases, compromising the server compromises all connected AI agents.
The Vulnerability
CVE-2026-9198 enables unauthenticated remote attackers to submit custom flow components that evaluate arbitrary Python code on the underlying host during flow compilation and execution.