CVE-2026-19298: Langflow is vulnerable to remote code execution due to authorization policy bypass in the authenticated flow-build endpoint
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process.
Other sources
Langflow OSS could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.11.3
Event History
Frequently Asked Questions
What level of access does an attacker need?
An attacker must be remote and authenticated. The advisory does not indicate that unauthenticated users can exploit the issue.
Which deployments are affected?
IBM Langflow OSS versions 1.0.0 through 1.11.2 are identified as affected. The provided information does not state whether any particular configuration changes exposure.
What is the potential impact of successful exploitation?
A successful attacker could execute arbitrary code. The reported severity vector indicates high impacts to confidentiality, integrity, and availability.