CyberRota Analysis
AI-GeneratedIBM Langflow OSS versions 1.0.0 to 1.11.1 are vulnerable to arbitrary code execution due to inadequate security restrictions on the A2A public endpoint. This critical vulnerability poses a significant risk, allowing remote attackers to exploit the flaw and potentially take control of affected systems. Organizations using these versions should prioritize immediate patching and mitigation efforts to safeguard their environments.
CVE
CVE-2026-19286
Severity
CRITICAL
CVSS
9.8
EPSS
0.62%
Original NVD Description
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint.
Related CVEs
Other vulnerabilities affecting the same vendor(s)