IBM Langflow OSS 1.0.0 — CVE-2026-9135 (Critical)

Date Jul 17, 2026
Type Vendor advisory
Signal Critical vendor advisory
Vendor / Product IBM · Langflow OSS 1.0.0
CVE CVE-2026-9135
Critical vendor advisory CVE-2026-9135

Summary

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard integration that bypasses the allow_custom_components=false security control. The vulnerability exists because the validation mechanism only checks the main component source code in node_template["code"]["value"] but fails to validate dynamic CodeInput fields that store generated ToolGuard Python files. Attackers can embed malicious Python code in these unvalidated dynamic fields, which are persisted i

Why it matters

This CVE carries a CRITICAL severity rating (CVSS 9.9) in IBM Langflow OSS 1.0.0. Patch or mitigate promptly.

Operator check

Review CVE-2026-9135 in your asset inventory. Apply patches per vendor guidance and verify Langflow OSS 1.0.0 is not exposed. CVSS score: 9.9.

Sources

PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.