Langflow OSS Security Update Advisory (CVE-2026-9198)
Overview
A security update has been released to address a vulnerability in Langflow OSS. This vulnerability, identified as CVE-2026-9198, is a remote code execution vulnerability that combines automatic login authentication bypass with the code validation feature.
Affected Versions
- Langflow OSS versions 1.0.0 Through 1.10.0 Are affected.
Resolution
- The Vulnerability Patch has been provided via the latest update.
- According to the reference materials, the patched version is 1.10.1.
Recommendations
- Langflow OSS users should update to the latest version with the Vulnerability Patch following the instructions on the reference site.
Reference
- Security Bulletin: Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation.