{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/langflow-oss-1.0.0---1.11.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ibm:langflow:*:*:*:*:oss:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-19286"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Langflow OSS (1.0.0 - 1.11.1)"],"_cs_severities":["critical"],"_cs_tags":["remote-code-execution","vulnerability","webserver"],"_cs_type":"advisory","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM Langflow OSS versions 1.0.0 through 1.11.1 are susceptible to a critical remote code execution (RCE) vulnerability identified as CVE-2026-19286. The issue arises from the improper enforcement of security restrictions on the A2A public endpoint. This flaw allows unauthenticated remote attackers to bypass authorization controls and execute arbitrary code on the underlying host. Given the nature of Langflow as a workflow automation and LLM orchestration tool, successful exploitation could grant an attacker full control over the application server, potentially allowing for data exfiltration, lateral movement, and the deployment of additional malicious payloads.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-19286 leads to full server compromise. Given the application's frequent deployment in cloud and containerized environments for AI/ML pipeline management, this vulnerability poses a severe risk to intellectual property and sensitive credentials stored within the workflow environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade to a version of Langflow OSS beyond 1.11.1 that addresses CVE-2026-19286.\u003c/li\u003e\n\u003cli\u003eImplement strict network access control lists (ACLs) to limit exposure of the A2A endpoint to known, trusted management segments.\u003c/li\u003e\n\u003cli\u003eMonitor web application logs for unexpected POST requests directed at the /api/a2a or similar A2A-prefixed endpoints originating from external or unauthorized IP addresses.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T23:34:49Z","date_published":"2026-08-28T23:34:49Z","id":"https://feed.craftedsignal.io/briefs/2026-08-langflow-rce/","summary":"IBM Langflow OSS versions 1.0.0 through 1.11.1 contain an unauthenticated remote code execution vulnerability in the A2A public endpoint.","title":"Remote Code Execution in IBM Langflow OSS via A2A Endpoint","url":"https://feed.craftedsignal.io/briefs/2026-08-langflow-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Langflow OSS (1.0.0 - 1.11.1)","version":"https://jsonfeed.org/version/1.1"}