CVE-CVE-2026-9198
Severity
CRITICAL
CVSS Score
9.8
Description
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments...
PoCs for CVE-CVE-2026-9198
PoC-CVE-2026-9198
General
Python
1
rmhowe425
2026-08-05
CVE-2026-9198
RCE
Python
0
K3ysTr0K3R
2026-08-22
cve-2026-9198_exploit
General
0
chessalekin
2026-08-23
EXPLOIT-CVE-2026-9198
General
Python
0
joaovicdev
2026-08-29