Langflow OSS Security Update Advisory (CVE-2026-9198)

Langflow OSS Security Update Advisory (CVE-2026-9198)

Overview


A security update has been released to address a vulnerability in Langflow OSS. This vulnerability, identified as CVE-2026-9198, is a remote code execution vulnerability that combines automatic login authentication bypass with the code validation feature.

Affected Versions


  • Langflow OSS versions 1.0.0 Through 1.10.0 Are affected.

Resolution


  • The Vulnerability Patch has been provided via the latest update.
  • According to the reference materials, the patched version is 1.10.1.

Recommendations


  • Langflow OSS users should update to the latest version with the Vulnerability Patch following the instructions on the reference site.

Reference


  • Security Bulletin: Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation.