{"data":{"id":"deeb3b27-d5b5-4b06-9c3c-515dbacc46c3","title":"CVE-2026-19294: IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute and read any user's private","summary":"IBM Langflow OSS (an open-source tool for building AI applications) versions 1.0.0 through 1.11.1 has a security flaw where someone who is logged into the system could view or run private workflows belonging to other users because the software doesn't properly check permissions (improper authorization, meaning the system doesn't verify who should have access to what).","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-19294","publishedAt":"2026-08-28T22:16:47.470Z","cveId":"CVE-2026-19294","cweIds":["CWE-639"],"cvssScore":"6.4","cvssSeverity":"medium","severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["IBM Langflow"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-28T22:16:47.470Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}