CVE-2026-12940
- EPSS 0.52%
- Veröffentlicht 30.07.2026 16:41:54
- Zuletzt bearbeitet 04.08.2026 20:20:28
IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py where t...
CVE-2026-13442
- EPSS 0.17%
- Veröffentlicht 28.07.2026 20:55:24
- Zuletzt bearbeitet 04.08.2026 20:11:02
IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only vector content and influence later query results. This causes cross-user information disclosure and limited integrity impact thro...
CVE-2026-13445
- EPSS 0.21%
- Veröffentlicht 17.07.2026 20:44:38
- Zuletzt bearbeitet 23.07.2026 05:16:27
IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read and modify another user's uploaded files by specifying absolute paths pointing to victim storage locations. In append mode, the atta...
CVE-2026-13446
- EPSS 0.23%
- Veröffentlicht 17.07.2026 20:43:49
- Zuletzt bearbeitet 23.07.2026 05:16:29
IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
CVE-2026-13448
- EPSS 0.46%
- Veröffentlicht 17.07.2026 20:03:30
- Zuletzt bearbeitet 23.07.2026 05:16:29
IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the public flow build endpoint ( /api/v1/build_public_tmp/{flow_id}/flow ). The vulnerability stems from an incomplete denylist in th...
CVE-2026-14499
- EPSS 0.45%
- Veröffentlicht 17.07.2026 19:57:05
- Zuletzt bearbeitet 23.07.2026 05:16:29
IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input in the Python Interpreter component.
CVE-2026-7667
- EPSS 0.36%
- Veröffentlicht 17.07.2026 19:21:41
- Zuletzt bearbeitet 23.07.2026 05:16:38
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacker-controlled URL that returns a specially crafted Content-Disposition header (e.g., filename="../../../target/path" ), enabling ar...
CVE-2026-7754
- EPSS 0.2%
- Veröffentlicht 17.07.2026 19:19:24
- Zuletzt bearbeitet 21.07.2026 16:17:21
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure default configuration and incomplete enforcement of the SSRF protection mechanism.
CVE-2026-7755
- EPSS 0.42%
- Veröffentlicht 17.07.2026 19:18:26
- Zuletzt bearbeitet 23.07.2026 05:16:38
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcement on MCP server configuration files.
CVE-2026-7872
- EPSS 0.36%
- Veröffentlicht 17.07.2026 19:15:11
- Zuletzt bearbeitet 20.07.2026 17:59:05
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication tokens for any user.