CVE-2026-10547
- EPSS 0.2%
- Veröffentlicht 05.08.2026 18:14:29
- Zuletzt bearbeitet 06.08.2026 19:34:08
IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/vertices endpoint, allowing an authenticated user to inject arbitrary graph data into a shared cache for any flow. This may resu...
CVE-2026-7869
- EPSS 0.2%
- Veröffentlicht 05.08.2026 18:13:15
- Zuletzt bearbeitet 06.08.2026 19:00:31
IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledge_bases`). This occurs because user-supplied knowledge base names are used directly to create file paths without proper sanitizati...
CVE-2026-8470
- EPSS 0.11%
- Veröffentlicht 05.08.2026 18:11:52
- Zuletzt bearbeitet 06.08.2026 18:52:08
IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under 32 characters. The deterministic Me...
CVE-2026-9205
- EPSS 0.21%
- Veröffentlicht 05.08.2026 18:09:11
- Zuletzt bearbeitet 07.08.2026 13:16:53
IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.
CVE-2026-10128
- EPSS 0.22%
- Veröffentlicht 05.08.2026 17:42:08
- Zuletzt bearbeitet 06.08.2026 19:00:35
IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbitrary server environment variables, exposing sensitive secrets despite security controls intended to disable custom components.
CVE-2026-9081
- EPSS 0.17%
- Veröffentlicht 05.08.2026 17:38:52
- Zuletzt bearbeitet 06.08.2026 18:16:55
IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the validate_model_provider_key() function for the Ollama provider. The function accepts a user-supplied OLLAMA_BASE_URL pa...
CVE-2026-7657
- EPSS 0.2%
- Veröffentlicht 05.08.2026 17:37:58
- Zuletzt bearbeitet 06.08.2026 18:17:23
IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplete and ineffective SSRF protection enforcement.
CVE-2026-17625
- EPSS 0.81%
- Veröffentlicht 05.08.2026 17:17:09
- Zuletzt bearbeitet 06.08.2026 19:08:16
IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands du...
CVE-2026-17623
- EPSS 0.94%
- Veröffentlicht 05.08.2026 16:34:22
- Zuletzt bearbeitet 06.08.2026 19:35:32
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of the command field in MCP server configurations.
CVE-2026-17630
- EPSS 0.42%
- Veröffentlicht 05.08.2026 16:33:46
- Zuletzt bearbeitet 07.08.2026 13:16:47
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper validation of configuration parameters.