Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments
CVE-2026-9198 is a code injection vulnerability (CWE-94) in IBM Langflow OSS versions 1.0.0 through 1.10.0. The flaw exists because the /api/v1/validate/code endpoint passes attacker-supplied Python code directly to exec(), evaluating decorators, default argument expressions, and annotations at function definition time. On default deployments, the auto-login feature is enabled, which means a companion endpoint issues SUPERUSER bearer tokens to any network caller without authentication. Together, these two design failures create a fully unauthenticated path to arbitrary code execution.
An attacker sends two crafted HTTP requests in sequence. The first targets /api/v1/auto_login, which returns a SUPERUSER bearer token to any caller without requiring credentials. The attacker then submits a second request to /api/v1/validate/code, presenting that token and carrying arbitrary Python code embedded in decorators or default argument expressions. The server passes this code to exec(), executing it with the privileges of the Langflow process. The result is full remote code execution: complete compromise of confidentiality, integrity, and availability on the host. No authentication, user interaction, or local access is required on default deployments.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
If IBM Langflow runs inside your authorization boundary, yes — CVE-2026-9198 affects your FedRAMP authorization. CISA has listed this vulnerability in its Known Exploited Vulnerabilities catalog, with a remediation deadline of August 7, 2026. An unpatched KEV inside your boundary is an assessor finding. You either remediate it before that date or formally document a mitigation — waiting for your agency or assessor to raise it is not a viable posture.
Knox does not patch your software. Remediating IBM Langflow is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus continuous compliance monitoring and audit-artifact coverage that document the fix for your next assessment. The work of applying the patch is yours; maintaining a compliant posture while you do it is not something you have to manage alone.
Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues, including CVE-2026-9198. Exposure surfaces during ongoing monitoring rather than only when an assessor flags it at review time, giving you the lead time to act before a finding becomes a formal conversation with your agency.
Book a meeting with Knox and map your path to authorization. Knox delivers FedRAMP in 90 days for 90% less, without the delays or dependencies of a traditional authorization build.
If CVE-2026-9198 is not remediated by August 7, 2026, it becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is precisely what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Meeting the deadline keeps your authorization clean and the agency relationship intact.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.











_Horizontal_RGB.png)









