CVE-2026-7524

IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links during archive extraction.

critical 9.8 CVSS 3.1
Published: May 27, 2026
Modified: Jun 2, 2026
Vendor: Langflow
Product: Langflow