CVE-2026-19295
Analyzed Analyzed - Analysis Complete

IBM Langflow OSS Remote Code Execution

Vulnerability report for CVE-2026-19295, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-09-01

Assigner: IBM Corporation

Description

IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references it. This allowed privilege escalation from "authenticated flow user" to arbitrary OS-level command execution under the server process identity, bypassing the LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false policy control.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-09-01
Generated
2026-09-18
AI Q&A
2026-08-29
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
langflow langflow From 1.0.0 (inc) to 1.11.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-95 The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call (e.g. "eval").

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to run arbitrary operating system commands on the server by creating a flow with a specially crafted type field value. When a wrapper flow referencing this malicious flow is built, it triggers the command execution, escalating privileges from a regular user to full system-level access under the server process identity. This bypasses the LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false policy control.

Detection Guidance

Detecting this vulnerability requires checking for unauthorized flow builds or suspicious type field values in IBM Langflow OSS. Review server logs for commands executed by authenticated users. Check for flows with unusual type field values or wrapper flows referencing modified flows. No specific commands are provided in the context.

Impact Analysis

If you use IBM Langflow OSS versions 1.0.0 to 1.11.1, an attacker with authenticated access could take over your server, steal data, install malware, or disrupt operations. This could lead to unauthorized access to sensitive information, system compromise, or complete control over the affected environment.

Compliance Impact

This vulnerability could severely impact compliance with GDPR, HIPAA, and other regulations. It allows unauthorized access to sensitive data, potentially violating confidentiality requirements. Organizations may face fines, legal penalties, and reputational damage due to data breaches resulting from this flaw.

Mitigation Strategies

Immediately upgrade IBM Langflow OSS to a version beyond 1.11.1. Disable custom component builds if not required. Review and remove any suspicious flows. Restrict authenticated user permissions to prevent privilege escalation. Monitor server logs for unusual activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19295. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart