System running
Last check: 2026-09-29 04:30:34 | Auto-updates every hour
756 PoCs
CybersecPlayground | The ultimate platform for cybersecurity learning & Bug Bounty Resources

CVE-CVE-2026-19295

Severity
CRITICAL
CVSS Score
9.9
Description

IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references it. This allowed privilege escalation from "authenticated flow user" to arbitrary OS-level command execution under the server process identity, bypassing the LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false policy control....

PoCs for CVE-CVE-2026-19295

POC-CVE-2026-19295
General Python 0
rmhowe425 2026-08-28
Master Cybersecurity | Join CybersecPlayground for Cybersecurity Learning & Bug Bounty Resources