← Back

CVE-2026-19295

nvd nist
Published: Aug 28, 2026Modified: Sep 1, 2026

JSON object

Loading...
9.9
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitability: 3.1 / Impact: 6.0
Source: psirt@us.ibm.com (Secondary)

Description

IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references it. This allowed privilege escalation from "authenticated flow user" to arbitrary OS-level command execution under the server process identity, bypassing the LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false policy control.

Affected (1)

Products: Langflow: Langflow
1 product
Langflow
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 1.0.0 to 1.11.2

References (1)

Source: psirt@us.ibm.com
Vendor Advisory

Timeline

No history available yet.