CVE-2026-19295
Last modified
CVE-2026-19295 is a critical-severity vulnerability rated 9.9/10 on the CVSS scale. IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references it. This allowed privilege escalation from "authenticated flow user" to arbitrary OS-level command execution under the server process identity, bypassing the LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false policy control.. EPSS estimates a 0.98% chance of exploitation in the next 30 days.
Description
IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references it. This allowed privilege escalation from "authenticated flow user" to arbitrary OS-level command execution under the server process identity, bypassing the LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false policy control.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Langflow | Langflow | >= 1.0.0, < 1.11.2 |
References
- https://www.ibm.com/support/pages/node/7284733Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-19295?
How severe is CVE-2026-19295?
How do I fix CVE-2026-19295?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-1929The Advanced Woo Labels plugin for WordPress is vulnerable t…8.8
- CVE-2026-19290IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6_1, 6.2.1.0…7.5
- CVE-2026-19291Bluetooth re-pairing with an existing device can use a lower…8.8
- CVE-2026-19292Re-pairing with a legitimate device can use a lower security…8.8
- CVE-2026-19293SMP security request (from peripheral) does not include the …8.8
- CVE-2026-19294IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote a…6.5
- CVE-2026-19297IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote at…9.1
- CVE-2026-19298IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote a…8.8
- CVE-2026-19299IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote a…6.5
- CVE-2026-1930The Emailchef plugin for WordPress is vulnerable to unauthor…4.3
- CVE-2026-19300IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote a…7.5
- CVE-2026-19301IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote a…6.5
Are you affected by CVE-2026-19295?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
