{
  "title": "CVE del giorno — CVE-2026-93674 (CVSS 9,8, critica) · Langflow",
  "title_variants": [
    {
      "id": "v0",
      "title": "CVE del giorno — CVE-2026-93674 (CVSS 9,8, critica) · Langflow"
    },
    {
      "id": "v1",
      "title": "Langflow · CVSS 9,8"
    },
    {
      "id": "v2",
      "title": "CVE-2026-93674 in Langflow: vulnerabilità critica, CVSS 9,8/10, tipo code"
    }
  ],
  "description": "CVE-2026-93674 in Langflow: vulnerabilità critica, CVSS 9,8/10, tipo code injection, sfruttabile da remoto, senza privilegi, senza interazione utente. IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of special elements…",
  "keywords": [
    "cve",
    "cve-2026-93674",
    "vulnerabilità",
    "vulnerabilità critica",
    "vulnerabilità langflow",
    "langflow cve",
    "patch langflow",
    "cwe-94",
    "cvss",
    "sicurezza informatica",
    "cybersecurity",
    "nvd"
  ],
  "scenes": [
    {
      "title": "CVE-2026-93674",
      "subtitle": "Langflow · CVSS 9,8",
      "text": "CVE-2026-93674 colpisce Langflow: gravità critica, punteggio CVSS 9,8 su 10 secondo il National Vulnerability Database."
    },
    {
      "title": "Code injection",
      "subtitle": "code injection · CVSS v3.1",
      "text": "IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command."
    },
    {
      "title": "ESPOSIZIONE E MITIGAZIONE",
      "subtitle": "sfruttabile da remoto, senza privilegi, senza interazione utente",
      "text": "Vulnerabilità sfruttabile da remoto, senza privilegi, senza interazione utente. Applica tempestivamente l'aggiornamento del fornitore e consulta l'avviso ufficiale su NVD."
    }
  ],
  "publication_date": "2026-10-09T00:36:52.098Z",
  "duration": 20,
  "topic": "cve",
  "lang": "it",
  "translation_group": "cve-2026-10-09",
  "poster": "cve-2026-10-09.jpg",
  "preview": "cve-2026-10-09.gif",
  "og_card": "cve-2026-10-09.og.jpg",
  "audiogram": "cve-2026-10-09.audiogram.mp4",
  "captions": "cve-2026-10-09.vtt",
  "generation": {
    "procedural": true,
    "ai_generated": [
      "background",
      "voice"
    ],
    "real_data_source": "official public API",
    "filmed_real_event": false,
    "disclosure": "Procedurally generated from real public-source data; abstract AI-generated backgrounds; synthetic (TTS) voice. No real event is filmed or altered."
  },
  "transcript_text": "CVE-2026-93674 colpisce Langflow: gravità critica, punteggio CVSS 9,8 su 10 secondo il National Vulnerability Database. IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. Vulnerabilità sfruttabile da remoto, senza privilegi, senza interazione utente. Applica tempestivamente l'aggiornamento del fornitore e consulta l'avviso ufficiale su NVD.",
  "transcript": [
    {
      "start": 0,
      "end": 6.667,
      "text": "CVE-2026-93674 colpisce Langflow: gravità critica, punteggio CVSS 9,8 su 10 secondo il National Vulnerability Database."
    },
    {
      "start": 6.667,
      "end": 13.333,
      "text": "IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command."
    },
    {
      "start": 13.333,
      "end": 20,
      "text": "Vulnerabilità sfruttabile da remoto, senza privilegi, senza interazione utente. Applica tempestivamente l'aggiornamento del fornitore e consulta l'avviso ufficiale su NVD."
    }
  ]
}