CVE-2026-12945

IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on log retrieval and unauthenticated build endpoints.
References
Link Resource
https://www.ibm.com/support/pages/node/7279994 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-30 17:16

Updated : 2026-08-04 20:19


NVD link : CVE-2026-12945

Mitre link : CVE-2026-12945

CVE.ORG link : CVE-2026-12945


JSON object : View

Products Affected

langflow

  • langflow
CWE
CWE-639

Authorization Bypass Through User-Controlled Key