Remote Code Execution Vulnerability in IBM Langflow OSS by IBM
CVE-2026-19875

7.5HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
19 August 2026

What is CVE-2026-19875?

The vulnerability in IBM Langflow OSS versions 1.0.0 through 1.10.0 stems from a flaw in the registration endpoint, allowing unauthorized remote attackers to overwrite administrator email information. This could potentially enable misuse of the server, allowing the compromised system to act as an outbound relay for malicious purposes.

Affected Version(s)

Langflow OSS 1.0.0 <= 1.10.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.