CVE-2026-19295
- EPSS 0.98%
- Veröffentlicht 28.08.2026 20:53:00
- Zuletzt bearbeitet 01.09.2026 04:18:00
IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references it. ...
CVE-2026-19294
- EPSS 0.2%
- Veröffentlicht 28.08.2026 20:52:38
- Zuletzt bearbeitet 31.08.2026 21:39:44
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute and read any user's private flow due to improper authorization.
CVE-2026-19286
- EPSS 0.61%
- Veröffentlicht 28.08.2026 20:52:24
- Zuletzt bearbeitet 01.09.2026 04:18:00
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint.
CVE-2026-18904
- EPSS 0.31%
- Veröffentlicht 28.08.2026 20:52:08
- Zuletzt bearbeitet 31.08.2026 21:44:55
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject unauthorized messages due to a namespace collision between user identifiers.
CVE-2026-18899
- EPSS 0.46%
- Veröffentlicht 28.08.2026 20:51:48
- Zuletzt bearbeitet 01.09.2026 02:16:57
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbitrary files due to path traversal.
CVE-2026-18891
- EPSS 0.29%
- Veröffentlicht 28.08.2026 20:51:27
- Zuletzt bearbeitet 31.08.2026 21:53:54
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitive information due to improper authentication.
CVE-2026-18729
- EPSS 0.46%
- Veröffentlicht 28.08.2026 20:49:43
- Zuletzt bearbeitet 01.09.2026 04:18:00
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.
CVE-2026-18545
- EPSS 0.2%
- Veröffentlicht 28.08.2026 20:49:25
- Zuletzt bearbeitet 31.08.2026 21:58:49
IBM Langflow OSS 1.0.0 through 1.11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attack...
CVE-2026-19875
- EPSS 0.36%
- Veröffentlicht 19.08.2026 17:38:06
- Zuletzt bearbeitet 26.08.2026 20:51:46
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email information and abuse the server as an outbound relay due to missing authentication for the registration endpoint.
CVE-2026-19297
- EPSS 0.42%
- Veröffentlicht 13.08.2026 20:46:44
- Zuletzt bearbeitet 26.08.2026 15:12:15
IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts.