Summary
CVE-2026-9198 is a critical unauthenticated remote code execution (RCE) vulnerability affecting IBM Langflow OSS versions 1.0.0 through 1.10.0. By chaining two API endpoints — an authentication bypass in /api/v1/auto_login and arbitrary Python code execution in /api/v1/validate/code — an unauthenticated network attacker can achieve full RCE on any default-configured Langflow deployment. IBM has assigned a CVSS v3.1 base score of 9.8 (Critical) and recommends immediate upgrade to version 1.10.1.
Technical details
- Root cause: Two combined flaws enable the exploit chain. First, the
/api/v1/auto_loginendpoint, whenAUTO_LOGINis enabled (the default configuration), issues long-lived SUPERUSER bearer tokens to any unauthenticated network caller with no credential check. Second, the/api/v1/validate/codeendpoint passes user-supplied Python code directly to Python’sexec()without sandboxing or input restrictions, including executing decorators and default argument expressions at function-definition time. - Trigger conditions: Default Langflow deployment with
AUTO_LOGIN=true(enabled out of the box); no authentication or special configuration required on the part of the attacker. - Attack vector: A two-step, fully unauthenticated network attack — (1) call
/api/v1/auto_loginto obtain a SUPERUSER bearer token; (2) use that token to submit a malicious Python payload to/api/v1/validate/code, triggering arbitrary code execution on the server. - Impact: Full remote code execution as the Langflow process user, with complete loss of confidentiality, integrity, and availability on the affected host.
Affected software
- IBM Langflow OSS versions 1.0.0 through 1.10.0 (inclusive)
Severity
CVSS v3.1 base score: 9.8 (Critical)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE: CWE-94 (Improper Control of Generation of Code – Code Injection)
Mitigation and recommended actions
- Immediate: Upgrade to Langflow OSS version 1.10.1, available on PyPI. IBM strongly recommends addressing this vulnerability immediately by upgrading to 1.10.1.
- IBM’s official security advisory documents no workarounds for this vulnerability; upgrading to version 1.10.1 is the only supported remediation.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

