I found a security flaw in IBM's Langflow and CrewAI that lets attackers reach internal networks. I've been auditing AI agent frameworks. These tools let language models browse the web, run shell commands, call APIs.
Source: [Dev.to](https://dev.to/su5hrut/cve-2026-19304-bypassing-ssrf-guards-with-parser-confusion-g0b)