IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow security restrictions and session isolation controls.
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/7286666 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-09-10 21:17
Updated : 2026-09-15 17:19
NVD link : CVE-2026-85025
Mitre link : CVE-2026-85025
CVE.ORG link : CVE-2026-85025
JSON object : View
Products Affected
langflow
- langflow
CWE
CWE-863
Incorrect Authorization
