IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context due to improper cache key isolation in the MCP Tools component.
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/7286662 |
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-14 21:17
Updated : 2026-09-15 18:17
NVD link : CVE-2026-12763
Mitre link : CVE-2026-12763
CVE.ORG link : CVE-2026-12763
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
