Junglewise Threat Intelligence

CVE-2026-19295: IBM Langflow OSS eval injection in schema creation

CVE-2026-19295 · Severity: critical · CVSS 9.9 · Published 2026-08-28

Technologies: IBM Langflow OSS, Langflow. Vendors: IBM, Langflow.

Executive brief

IBM Langflow is a visual workflow automation platform that allows users to build and execute data processing and AI pipelines. An authenticated attacker can execute arbitrary operating system commands on the server by crafting malicious flow configurations, achieving complete system compromise. This bypasses intended security policies designed to prevent custom code execution.

Technical details

The vulnerability is an eval injection (CWE-95) in the create_input_schema_from_dict function, where attacker-controlled flow template type field strings reach Pydantic's ForwardRef evaluation path. This path internally calls eval() with an unrestricted builtins namespace, allowing arbitrary Python code execution. An authenticated attacker can save a flow with a crafted type field value and trigger a build of a wrapper flow that references it, executing arbitrary OS commands under the server process identity. The attack bypasses the LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false policy control. This requires authentication but no user interaction. IBM has released a fix in version 1.11.2.

Affected products

  • IBM Langflow OSS 1.0.0 through 1.11.1

Timeline

  • 2026-08-28: disclosed
  • 2026-08-28: patched: Fix available in version 1.11.2

References

Related threats