info: name: langflow author: A.I.G bot cve: CVE-2026-13435 severity: CRITICAL details: IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation. The vulnerability arises from insufficient validation of user-supplied input passed to the PythonREPL component, which is intended to execute Python code within a restricted sandbox environment. Due to inadequate input sanitization and sandbox boundary enforcement, an authenticated low-privileged attacker can craft malicious input that escapes the intended sandbox restrictions, leading to arbitrary Python code execution on the underlying server. This results in full confidentiality, integrity, and availability impact, enabling remote code execution with scope change. security_advise: Follow official security advisories and upgrade to a version later than 1.10.1. cvss: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H summary: langflow IBM Langflow OSS 1 rule: version >= "1.0.0" && version <= "1.10.1" references: - https://www.ibm.com/support/pages/node/7279987