CVE-2026-7803

langflow: Improper Input Validation (CVE-2026-7803)

criticalEPSS 0.6 %

Beschreibung

IBM Langflow OSS-Versionen von 1.0.0 bis 1.10.0 könnten die Ausführung beliebigen Codes ermöglichen, da Flussknoten aufgrund fehlerhafter Validierung mit fehlenden oder leeren Komponententyp-Feldern nicht korrekt überprüft werden.

Quelle: CVELISTV5NVD

Metriken

Severity
critical
kein öffentlicher PoC bekannt
9.8
Quelle: nvd-v3
48.8 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.6 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-06-30 19:15 UTC
CWE-20

Weakness-Klassen (CWE)

  • CWE-20Class

    Improper Input Validation

    The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. Initial Analysis2026-07-02 19:15 UTC· nvd@nist.gov
    • CWE: NVD-CWE-noinfo
    • CPE Configuration: OR *cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* versions from (including) 1.0.0 up to (including) 1.10.0
    • Reference Type: IBM Corporation: https://www.ibm.com/support/pages/node/7278445 Types: Vendor Advisory
  2. CVE Modified2026-06-30 20:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-7803","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalI…
  3. New CVE Received2026-06-30 20:17 UTC· psirt@us.ibm.com
    • Affected: Langflow OSS
    • Description: IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validation of flow nodes with missing or empty component type fields.
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    • CWE: CWE-20

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • langflow

    langflow1.0.0 – 1.10.0

Quellen & Referenzen

Verknüpfte Empfehlungen

IDCVE-2026-7803