CVE-2026-85025

IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow security restrictions and session isolation controls.
References
Link Resource
https://www.ibm.com/support/pages/node/7286666 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-09-10 21:17

Updated : 2026-09-15 17:19


NVD link : CVE-2026-85025

Mitre link : CVE-2026-85025

CVE.ORG link : CVE-2026-85025


JSON object : View

Products Affected

langflow

  • langflow
CWE
CWE-863

Incorrect Authorization