Vulnerability Description
IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validation of flow nodes with missing or empty component type fields.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Langflow | Langflow | >= 1.0.0, <= 1.10.0 |
Related Weaknesses (CWE)
References
- https://www.ibm.com/support/pages/node/7278445Vendor Advisory
FAQ
What is CVE-2026-7803?
CVE-2026-7803 is a vulnerability with a CVSS score of 9.8 (CRITICAL). IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validation of flow nodes with missing or empty component type fields.
How severe is CVE-2026-7803?
CVE-2026-7803 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-7803?
Check the references section above for vendor advisories and patch information. Affected products include: Langflow Langflow.