PoC Archive PoC Archive

tag

Python-Exec

  • CVE-2026-9198 web CRITICAL 9.8 KEV EPSS 17%

    IBM Langflow OSS Unauthenticated RCE via Auto-Login + validate/code Chain (CVE-2026-9198)

    IBM Langflow OSS ships an /api/v1/autologin endpoint that, when the deployment has LANGFLOWAUTOLOGIN enabled (a common/default posture), will mint and hand back a fully-privileged SUPERUSER JWT access token to any caller — no credentials, no session, nothing.…

    Patched 2026-07-31
  • CVE-2025-3248 web CRITICAL 9.8 KEV Ransomware EPSS 100%

    Langflow Missing-Authentication Remote Code Execution (CVE-2025-3248)

    CVE-2025-3248 is a missing-authentication vulnerability in Langflow's code-validation API. The /api/v1/validate/code endpoint accepts and executes arbitrary Python code submitted by any client, with no authentication check on the route, allowing an…

    Patched 2026-07-03