CVE-2026-12946
Homebrew vulnerability analysis and mitigation

Overview

CVE-2026-12946 is a critical code injection vulnerability in IBM Langflow OSS that allows a remote, low-privileged attacker to inject and execute arbitrary code on the affected system. It affects IBM Langflow OSS versions 1.0.0 through 1.10.0, with version 1.10.1 being the first patched release. The vulnerability was published on July 30, 2026, with a GitHub Advisory (GHSA-mj9q-p4gc-9rw2) published the same day. It carries a CVSS v3.1 base score of 9.9 (Critical) (GitHub Advisory, IBM Advisory).

Technical details

The root cause is classified as CWE-94 (Improper Control of Generation of Code / 'Code Injection'), where user-supplied input is incorporated into code segments without adequate neutralization or validation. An authenticated attacker with low privileges can submit malicious input over the network that is interpreted and executed as code by the application, with no user interaction required. The changed scope (S:C) in the CVSS vector indicates that successful exploitation can impact resources beyond the vulnerable component itself, such as the underlying host or connected services. No public proof-of-concept code has been identified at this time (GitHub Advisory, IBM Advisory).

Impact

Successful exploitation grants an attacker the ability to execute arbitrary code on the host system, resulting in high impact to confidentiality, integrity, and availability. Because the CVSS scope is marked as Changed, the impact extends beyond the Langflow application itself — attackers could potentially access sensitive data, modify or destroy system resources, disrupt service availability, and pivot to other connected systems or services. The combination of network accessibility, low privilege requirement, and full CIA impact makes this vulnerability particularly severe in multi-tenant or shared infrastructure environments (GitHub Advisory, IBM Advisory).

Exploitability

As of the time of reporting, there is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit. The NVD SSVC assessment indicates exploitation status as 'none' and the attack is not fully automatable (requires low-privilege authentication). The EPSS score is approximately 0.34–0.35%, placing it in roughly the 28th percentile for exploitation likelihood within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, IBM Advisory).

Mitigation and workarounds

IBM has released a patch in Langflow OSS version 1.10.1, which addresses this vulnerability; users should upgrade immediately from any version in the 1.0.0–1.10.0 range. Until an upgrade can be applied, organizations should restrict network access to IBM Langflow OSS instances to trusted and authenticated users only, implement network segmentation to limit the blast radius of potential exploitation, and consider disabling the application if it is not business-critical. Monitoring for anomalous code execution activity on hosts running Langflow OSS is also recommended as a compensating control (IBM Advisory, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Homebrew vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-73939HIGH8.6
  • Homebrew logoHomebrew
  • helidon
NoNoAug 18, 2026
CVE-2026-73937HIGH8.2
  • Homebrew logoHomebrew
  • helidon
NoNoAug 18, 2026
CVE-2026-73938HIGH7.5
  • Homebrew logoHomebrew
  • helidon
NoNoAug 18, 2026
CVE-2026-73936HIGH7.5
  • Homebrew logoHomebrew
  • helidon
NoNoAug 18, 2026
CVE-2026-73935HIGH7.5
  • Homebrew logoHomebrew
  • helidon
NoNoAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management