SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-19295

CRITICAL · CVSS 9.9 EPSS 0.96%

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-08

CyberRota Analysis

AI-Generated

IBM Langflow OSS versions 1.0.0 to 1.11.1 are vulnerable to a critical flaw that enables authenticated attackers to execute arbitrary operating system commands by manipulating flow configurations. This vulnerability allows privilege escalation from an authenticated user to arbitrary command execution at the server process level, circumventing existing security controls. Organizations using affected versions should prioritize immediate remediation to mitigate the risk of exploitation.

CVE
CVE-2026-19295
Severity
CRITICAL
CVSS
9.9
EPSS
0.96%

Original NVD Description

IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references it. This allowed privilege escalation from "authenticated flow user" to arbitrary OS-level command execution under the server process identity, bypassing the LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false policy control.

Related CVEs

Other vulnerabilities affecting the same vendor(s)