Vulnerability threat dossier

CVE-2026-18729

langflowlangflow

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.

VTP deterministic threat9.9of 100 · CVSS excluded

VTP analyst assessment

IBM Langflow authenticated code generation flaw

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence90%
Public exploitation · VTP factUNKNOWN

Assessment

Langflow OSS 1.0.0 through 1.11.1 permits authenticated remote code execution through improper code generation controls. Metasploit coverage is public.

Why it matters

  • An authenticated user could execute arbitrary code on an affected Langflow service.
  • If you use affected Langflow, update and restrict access to trusted users until remediation is complete.

Evidence

2 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

Public tooling availability does not establish active exploitation.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

Monitor unusual flow activity and server processes spawned by Langflow.

AI baseline history (2)
  1. BASELINE ASSESSED
    IBM Langflow authenticated code generation flawgpt-5.6-terra · low
  2. BASELINE ASSESSED
    Public exploit-oriented template reported for an unclassified CVEgpt-5.6-terra · low
Technical severityHIGHCVSS 8.8 · technical context
Public exploitationUNKNOWNGlobal public evidence
Exploit maturityPOCReliability not implied
EPSS0.0279th percentile · prediction
Evidence confidence90%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    A proof of concept is reported; functional reliability is not established.

  2. 02

    EPSS is 0.02; this is predictive context, not exploitation evidence.

  3. 03

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

EXPLOIT TEMPLATE AVAILABLEPublic exploit-oriented template available
03

Claim provenance

Evidence and source independence

1publications detected
1underlying evidence chains

0 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOIT TEMPLATE AVAILABLEPUBLIC EXPLOIT TEMPLATE
90%claim confidence
PRIMARYcorpus:METASPLOIT:28215e80b88f77d1478deaf4a93b02da80371551ACTIVE
Evidence
04

Event history

Threat timeline

  1. 19:0611 Sept
    EXPLOIT TEMPLATE AVAILABLE

    Public exploit-oriented template available

    Rapid7 Metasploit Framework published new or materially changed exploit-oriented tooling for this CVE. This is availability evidence, not evidence of exploitation in the wild.

05

Original publications

Source record

Exploit tooling coverage changed for 1 CVE

Rapid7 Metasploit Framework recorded exploit-tooling coverage changes for 1 CVE in this pinned revision. 1 have an active availability assertion for this revision. Tooling evidence does not establish exploitation in the wild or successful execution.

CVE-2026-18729
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score9.9vtp-threat-v1-public
Public exploitation0 / 30
EPSS prediction0.39 / 20
Exploit availability7.5 / 15
Source independence0 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
8.8 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-94
CPE records
1
Deterministic history records
13
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.