Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-19295

Опубликовано: 28 авг. 2026
Источник: nvd
CVSS3: 9.9
EPSS Низкий

Описание

IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references it. This allowed privilege escalation from "authenticated flow user" to arbitrary OS-level command execution under the server process identity, bypassing the LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false policy control.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*
Версия от 1.0.0 (включая) до 1.11.2 (исключая)

EPSS

Процентиль: 78%
0.01809
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-95

Связанные уязвимости

CVSS3: 9.9
github
23 дня назад

IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references it. This allowed privilege escalation from "authenticated flow user" to arbitrary OS-level command execution under the server process identity, bypassing the LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false policy control.

CVSS3: 9.9
fstec
28 дней назад

Уязвимость программного обеспечения для визуальной разработки ИИ-агентов IBM Langflow OSS, связанная с непринятием мер по нейтрализации инструкций в динамически исполняемом коде, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 78%
0.01809
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-95