Summary
CVE-2026-10561 is a critical unauthenticated remote code execution vulnerability in IBM Langflow OSS versions 1.0.0 through 1.9.3, assigned a maximum CVSS v3.1 base score of 10.0. The flaw combines improper isolation of Python execution in the PythonREPLComponent with an authentication bypass stemming from the platform’s default auto-login configuration, enabling any unauthenticated network attacker to execute arbitrary code on the host system and achieve complete system compromise.
Technical details
- Root cause (code injection): The
PythonREPLComponent‘sget_globals()method constructs a restricted globals dictionary for sandboxed Python execution but does not explicitly setglobals_["builtins"] = {}. When builtins are absent, Python’sexec()function automatically injects the full builtins module, defeating the intended whitelist and exposing unrestricted access to import statements, file I/O, and other dangerous built-in functions (CWE-94: Improper Control of Generation of Code). - Root cause (authentication bypass): Langflow OSS ships with
LANGFLOW_AUTO_LOGIN=trueas a default configuration value, which causes the platform to issue superuser-level JWT tokens without requiring credentials. This grants any unauthenticated request the privileges needed to reach the Python execution component. - Trigger conditions: No authentication, prior account, or user interaction is required. An attacker need only send a crafted network request to the Langflow API endpoint backed by the
PythonREPLComponent. - Attack vector: Network-accessible; Langflow exposes an HTTP/HTTPS API and web interface that is routinely deployed facing the public internet.
- Impact: Arbitrary OS command execution at the privilege level of the Langflow backend process, credential and secret exfiltration, persistent system compromise, flow and data tampering.
Affected software
- IBM Langflow OSS 1.0.0 through 1.9.3 (all versions in this range are affected)
Severity
- CVSS v3.1 Base Score: 10.0 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H- Attack Vector: Network | Attack Complexity: Low | Privileges Required: None | User Interaction: None | Scope: Changed | Confidentiality/Integrity/Availability: High
Mitigation and recommended actions
- Immediate action — patch: IBM strongly recommends upgrading to Langflow OSS 1.9.4, which addresses both the Python execution isolation flaw and the authentication bypass.
- If immediate patching is not possible:
- Set
LANGFLOW_AUTO_LOGIN=falsein your Langflow environment configuration to disable unauthenticated token issuance and require explicit credential-based authentication. - Restrict network access to Langflow API and UI endpoints via firewall rules or a reverse proxy, preventing exposure to untrusted networks until the patch can be applied.
- Monitor Langflow process activity for unexpected child process spawning or outbound network connections indicative of post-exploitation behavior.
- Set
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

