CVE-2026-19286: Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint.
Other sources
Langflow OSS could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.11.2
Event History
Frequently Asked Questions
Which deployments are exposed?
IBM Langflow OSS versions 1.0.0 through 1.11.1 are identified as affected. The issue concerns the A2A public endpoint.
What does an attacker need to exploit this issue?
The reported vector is network-based, requires low attack complexity, and does not require privileges or user interaction. A remote attacker could execute arbitrary code through insufficiently enforced security restrictions on the A2A public endpoint.
What is the potential impact of successful exploitation?
Successful exploitation could result in arbitrary code execution and is rated critical with high confidentiality, integrity, and availability impact.