Description
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint.
Published: 2026-08-28
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a remote code execution flaw caused by improper enforcement of security restrictions on the A2A public endpoint of IBM Langflow OSS. An attacker can send specially crafted input that bypasses the intended code‑execution policy, allowing execution of arbitrary code within the hosting environment. Affected systems

Affected Systems

IBM Langflow OSS versions 1.0.0 through 1.11.1 are affected. The vulnerability exists in the A2A public endpoint across these releases, and no later version is known to be impacted. Risk and exploitability

Risk and Exploitability

The CVSS score of 9.8 indicates a critical risk with high impact and full remote attack vectors. The EPSS score is not available, so the exact probability cannot be quantified, but the absence of a KEV listing suggests the vulnerability has not yet been widely exploited. The attack vector is inferred to be remote through the A2A public API, requiring the ability to send crafted requests to the endpoint. Once exploited, an attacker could execute arbitrary code on the host, compromising confidentiality, integrity, and availability.

Generated by OpenCVE AI on August 28, 2026 at 23:23 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.11.2 https://pypi.org/project/langflow/


OpenCVE Recommended Actions

  • Upgrade IBM Langflow OSS to version 1.11.2 or later as recommended by IBM.
  • Disable or restrict access to the A2A public endpoint to prevent external exploitation.
  • Configure the application’s code‑execution policy to enforce strict validation and isolation of user‑provided code segments.

Generated by OpenCVE AI on August 28, 2026 at 23:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint.
Title Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-94
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.11.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Langflow Oss
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-28T20:52:24.166Z

Reserved: 2026-08-07T15:36:51.777Z

Link: CVE-2026-19286

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T22:16:47.357

Modified: 2026-08-28T22:16:47.357

Link: CVE-2026-19286

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T23:30:17Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')