CVE-2026-19298
moderateAuthenticated RCE via authorization bypass in IBM Langflow OSS 1.0.0–1.11.2
IBM Langflow OSS versions 1.0.0 through 1.11.2 contain an authorization bypass (code injection, CWE-94) in the flow build process, allowing attackers to execute arbitrary code. The flaw is triggered remotely by any attacker holding valid low-privilege credentials, who sends crafted requests to the flow build process where insufficient authorization checks permit injected code to run. Successful exploitation yields arbitrary code execution on the server with the service's privileges, with high impact to confidentiality, integrity, and availability (CVSS 3.1: 8.8). Any organization running Langflow OSS 1.0.0–1.11.2 is affected, particularly self-hosted instances exposed to the internet. There is no known exploitation in the wild, no public proof-of-concept, and a low predicted exploitation probability (EPSS 0.5%), and the issue is not in CISA's KEV catalog.
What to do: Upgrade Langflow OSS from the affected 1.0.0–1.11.2 range to a fixed release newer than 1.11.2, checking IBM's and Langflow's advisories for the exact fixed version. Until upgraded, avoid exposing Langflow to the public internet, restrict which accounts hold credentials, and review access to the flow build endpoint. Defenders can confirm their deployed version and whether instances are internet-exposed.
| IBM Langflow OSS | 1.0.0 through 1.11.2 (inclusive) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process.
- Vendors
- langflow
- Products
- langflow
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.