[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-19295":6},{"stargazers_count":4,"fetched_at":5},7,"2026-08-28T22:53:37.900Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":54,"aliases":55,"duplicate_of":9,"upstream":56,"downstream":57,"duplicates":58,"related":59,"reserved_at":9,"published_at":60,"modified_at":60,"state":61,"summary":62,"references_raw":69,"kevs":77,"epss":9,"epss_history":78,"metrics":79,"affected":87},"CVE-2026-19295","IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references it. This allowed privilege escalation from \"authenticated flow user\" to arbitrary OS-level command execution under the server process identity, bypassing the LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false policy control.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-95","Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')","The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call (e.g. \"eval\").","weakness","Incomplete","Variant","Medium",[20],{"id":21,"name":22,"techniques":23},"CAPEC-35","Leverage Executable Code in Non-Executable Files",[24,35,42],{"id":25,"name":26,"tactics":27,"countermeasures":34},"T1027.006","HTML Smuggling",[28,31],{"id":29,"name":30},"TA0030","Defense Evasion",{"id":32,"name":33},"TA0005","Stealth",[],{"id":36,"name":37,"tactics":38,"countermeasures":41},"T1027.009","Embedded Payloads",[39,40],{"id":29,"name":30},{"id":32,"name":33},[],{"id":43,"name":44,"tactics":45,"countermeasures":48},"T1564.009","Resource Forking",[46,47],{"id":29,"name":30},{"id":32,"name":33},[49],{"id":50,"name":51,"tactic":52},"D3-FFV","File Format Verification",{"name":53},"Isolate",[],[],[],[],[],[],"2026-08-28T20:53:00.278Z","Received",{"cisa_kev":63,"cisa_ransomware":63,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":64,"severity_score":65,"severity_version":66,"severity_source":67,"severity_vector":68,"severity_status":61},false,"critical",9.9,"v3.1","cve.org","CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",[70],{"url":71,"sources":72,"tags":74},"https://www.ibm.com/support/pages/node/7284733",[67,73],"nvd",[75,76],"Vendor Advisory","Patch",[],[],[80,85],{"source":67,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":81,"cvss_v4_0":9},{"baseScore":65,"baseSeverity":82,"vectorString":68,"impactScore":83,"exploitabilityScore":84},"CRITICAL",10,7.9,{"source":73,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":86,"cvss_v4_0":9},{"baseScore":65,"baseSeverity":82,"vectorString":68,"impactScore":83,"exploitabilityScore":84},[88],{"ecosystem":9,"name":89,"vendor":90,"product":91,"cpe_part":92,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":93},"Langflow OSS","ibm","langflow oss","a",[94],{"version":95,"is_range":96,"range_type":67,"version_start":97,"version_start_type":98,"version_end":99,"version_end_type":98,"fixed_in":9},">= 1.0.0, \u003C= 1.11.1",true,"1.0.0","including","1.11.1"]