top of page
perceptive_background_267k.jpg

IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow wit…

Published:

28 August 2026 at 00:00:00

Alert date:

29 August 2026 at 01:06:09

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Zero-Day Vulnerabilities, Identity & Access

CVE-2026-19295 affects IBM Langflow OSS versions 1.0.0 through 1.11.1, allowing an authenticated attacker to execute arbitrary operating system commands on the server. The attack vector involves saving a flow with a crafted type field value and triggering a build of a wrapper flow that references it. This vulnerability enables privilege escalation from an authenticated flow user to arbitrary OS-level command execution under the server process identity. Critically, it bypasses the LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false policy control, rendering that security configuration ineffective. The vulnerability is classified as high severity given the potential for full server compromise by any authenticated user. Organizations running affected versions of IBM Langflow OSS should apply patches or mitigations immediately as described in IBM's security advisory.

Technical details

Mitigation steps:

Affected products:

IBM Langflow OSS 1.0.0
IBM Langflow OSS 1.11.1

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page