PoC Index82,591 CVEs with PoCs

CVE-2026-10134

Unauthenticated Server-Side RCE via PythonCodeStructuredTool in Public Flows

CRITICAL 10.0EPSS 0.6%

IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversation, message, file upload, and saved component in the Langflow database, can connect to internal services, abuse cloud metadata endpoints, laterally move to other tenants on the same Langflow instance, and Establish persistence by modifying the public flow's `tool_code` so normal `/api/v1/build/...` calls by any user re-execute attacker code at each build.

Affected
IBM · Langflow OSS
CVSS v3.1 ibm
10.0 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS
0.64% chance of exploitation in the next 30 days, 48th percentile
Published
2026-06-30
Updated
2026-07-01

Proof-of-concept exploits (1)

References

Related