Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-19295: IBM Langflow lets logged-in user run OS commands

CVE-2026-19295 · published 6 days ago
Summary

Versions 1.0.0 through 1.11.1 of IBM Langflow allow someone who has a regular account to make the software run any command on the server. This can let an attacker take control of the machine that hosts the application. Upgrade to the latest version and limit access to trusted users only.

What to do
  • Update langflow langflow to version 1.11.2 or later.
Affected software
VendorProductAffected versions
ibm langflow oss <= 1.11.1
langflow langflow >= 1.0.0, < 1.11.2
cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*
Original advisory text
IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and trig...
IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references it. This allowed privilege escalation from "authenticated flow user" to arbitrary OS-level command execution under the server process identity, bypassing the LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false policy control.
References
Severity
9.9 Critical
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-95Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
Timeline
Published28 Aug 2026
Updated2 Sep 2026
First seen28 Aug 2026
Sources
CVE-2026-19295 · MITRE
Monitor software like this
Free during beta