PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-93447 IBM CVE debrief

IBM Langflow OSS 1.0.0 through 1.12.2 could allow an attacker with access to the server secret and Redis write access to submit a malicious serialized cache value. When the value was retrieved, deserialization could have executed attacker-controlled code with the privileges of the service process. This vulnerability is a high-severity issue that requires immediate attention from defenders. The affected product is widely used, and exploitation could lead to significant operational impacts.

Vendor
IBM
Product
Langflow OSS
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for IBM Langflow OSS deployments should assess exposure and prioritize remediation. This includes operators, platform administrators, vulnerability management teams, and security teams. They should verify Langflow OSS presence, review access controls, and apply patches to prevent potential code execution with service process privileges and unauthorized access to sensitive data.

Why it matters

CVE-2026-93447 is a high-severity vulnerability in IBM Langflow OSS that could allow attackers to execute malicious code. Defenders should verify Langflow OSS presence, review access controls, and apply patches.

  • Potential code execution with service process privileges
  • Possible unauthorized access to sensitive data
  • Required verification of Langflow OSS presence and version
  • Necessity to review and restrict server secret and Redis access

Technical summary

IBM Langflow OSS 1.0.0 through 1.12.2 is vulnerable to deserialization of untrusted data. An attacker with access to the server secret and Redis write access could submit a malicious serialized cache value, which when retrieved, could execute attacker-controlled code with the privileges of the service process. This vulnerability is a high-severity issue that requires immediate attention from defenders. The affected product is widely used, and exploitation could lead to significant operational impacts. Defenders should prioritize verifying the presence of Langflow OSS within their environment, reviewing server secret and Redis access controls, and applying vendor-provided patches.

Defensive priority

Defenders should prioritize verifying the presence of Langflow OSS within their environment, reviewing server secret and Redis access controls, and applying vendor-provided patches.

Recommended defensive actions

  • Verify Langflow OSS presence in environment
  • Review server secret and Redis access controls
  • Apply vendor-provided patches
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions, retest remediated assets
  • Plan vendor-supported updates or mitigations

Evidence notes

The CVE record and source item provide details on the vulnerability in IBM Langflow OSS. The NVD entry is currently being processed. Defenders should verify Langflow OSS presence, review access controls, and apply patches. Evidence is limited, and further verification is required to confirm affected scope and severity. The vulnerability is confirmed, but details on exploitation are not publicly available.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-93447 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-93447

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-93447 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93447

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Langflow OSS is affected by multiple vulnerabilities

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/93xxx/CVE-2026-93447.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://www.ibm.com/support/pages/node/7290694

    Supplemental source - vendor-advisory, patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.