CVE-2026-9135
A code injection vulnerability exists in the Policies component's ToolGuard integration within IBM Langflow. It allows attackers to bypass security controls by embedding malicious Python code into unvalidated dynamic fields.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Users of IBM Langflow OSS versions 1.0.0 through 1.10.0, specifically those using versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d).
Real-world impact
An attacker can execute arbitrary Python code on the server. This can be achieved by injecting malicious code into a victim's flow, potentially allowing for cross-tenant data manipulation or full system compromise.
Why this severity
The critical score reflects that an attacker can achieve full control over the server (high impact on confidentiality, integrity, and availability) via a network-based attack with low complexity.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
NVD description
Timeline
- Jul 17, 2026 · 16d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 10d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- ibm.com/support/pages/node/7278920vendor advisory