CVE-2026-19295
published 2026-08-28CVE-2026-19295: IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow…
PriorityP274critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EXPLOIT
EPSS
3.27%
88.0th percentile
IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references it. This allowed privilege escalation from "authenticated flow user" to arbitrary OS-level command execution under the server process identity, bypassing the LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false policy control.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | langflow_oss | 1.0.0 – 1.11.1 | — |
| langflow | langflow | >= 1.0.0 < 1.11.2 | 1.11.2 |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM Langflow OSS up to 1.11.1 Build Trigger Type privileges management
vuldb·2026-08-29·CVSS 9.9
CVE-2026-19295 [CRITICAL] IBM Langflow OSS up to 1.11.1 Build Trigger Type privileges management
A vulnerability marked as critical has been reported in IBM Langflow OSS up to 1.11.1. Affected by this issue is some unknown functionality of the component Build Trigger. This manipulation of the argument Type causes improper privilege management.
This vulnerability is registered as CVE-2026-19295. Remote exploitation of the attack is possible. No exploit is available.
GHSA
IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and trigger
ghsa_unreviewed·2026-08-29
CVE-2026-19295 [CRITICAL] CWE-95 IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and trigger
IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references it. This allowed privilege escalation from "authenticated flow user" to arbitrary OS-level command execution under the server process identity, bypassing the LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false policy control.
No detection rules found.
2026-08-28
Published