Skip to content
COOEY

EXPOSURES › CVE-2026-13448

CVE-2026-13448

HIGH
DETAIL
SourceNVD · cve Published2026-07-17 CVSS8.1 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-13448 ↗

▸ RECOMMENDED ACTION  Patch the affected products and confirm your instances are covered.

DESCRIPTION

IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the public flow build endpoint ( /api/v1/build_public_tmp/{flow_id}/flow ). The vulnerability stems from an incomplete denylist in the validate_public_flow_no_code_execution() function that fails to block several code-execution agent components including OpenDsStarAgent, CodeActAgentSmolagents, and CSVAgent.

AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized