ZeroHour

CVE-2026-19298

moderate

Authenticated RCE via authorization bypass in IBM Langflow OSS 1.0.0–1.11.2

CVSS 3.1
8.8 high
EPSS
<1%p41
Published
()
Modified
AI analysis

IBM Langflow OSS versions 1.0.0 through 1.11.2 contain an authorization bypass (code injection, CWE-94) in the flow build process, allowing attackers to execute arbitrary code. The flaw is triggered remotely by any attacker holding valid low-privilege credentials, who sends crafted requests to the flow build process where insufficient authorization checks permit injected code to run. Successful exploitation yields arbitrary code execution on the server with the service's privileges, with high impact to confidentiality, integrity, and availability (CVSS 3.1: 8.8). Any organization running Langflow OSS 1.0.0–1.11.2 is affected, particularly self-hosted instances exposed to the internet. There is no known exploitation in the wild, no public proof-of-concept, and a low predicted exploitation probability (EPSS 0.5%), and the issue is not in CISA's KEV catalog.

What to do: Upgrade Langflow OSS from the affected 1.0.0–1.11.2 range to a fixed release newer than 1.11.2, checking IBM's and Langflow's advisories for the exact fixed version. Until upgraded, avoid exposing Langflow to the public internet, restrict which accounts hold credentials, and review access to the flow build endpoint. Defenders can confirm their deployed version and whether instances are internet-exposed.

Affected
IBM Langflow OSS1.0.0 through 1.11.2 (inclusive)
Estimated exposure
moderateon the order of 10,000–100,000 self-hosted instances/deployments worldwide — Langflow OSS is a widely adopted open-source LLM workflow tool typically self-hosted by developers and enterprises, and public internet-wide scans have catalogued thousands of Langflow instances on its default port, so the global installed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process.

Vendors
langflow
Products
langflow
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.