CVE-2026-7803
langflow: Improper Input Validation (CVE-2026-7803)
criticalEPSS 0.6 %
Beschreibung
Metriken
Severity
critical
102.15
kein öffentlicher PoC bekannt
9.8
Veröffentlicht
2026-06-30 19:15 UTC
CWE-20
Weakness-Klassen (CWE)
CWE-20Class
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- Initial Analysis2026-07-02 19:15 UTC· nvd@nist.gov
- CWE: NVD-CWE-noinfo
- CPE Configuration: OR *cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* versions from (including) 1.0.0 up to (including) 1.10.0
- Reference Type: IBM Corporation: https://www.ibm.com/support/pages/node/7278445 Types: Vendor Advisory
- CVE Modified2026-06-30 20:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-7803","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalI…
- New CVE Received2026-06-30 20:17 UTC· psirt@us.ibm.com
- Affected: Langflow OSS
- Description: IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validation of flow nodes with missing or empty component type fields.
- CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CWE: CWE-20
Betroffene Produkte
Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.
langflow
langflow1.0.0 – 1.10.0
Quellen & Referenzen
Verknüpfte Empfehlungen
IDCVE-2026-7803