CVE-2026-19298
- EPSS 0.47%
- Veröffentlicht 04.09.2026 16:17:21
- Zuletzt bearbeitet 10.09.2026 16:17:09
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process.
CVE-2026-19300
- EPSS 0.38%
- Veröffentlicht 04.09.2026 15:47:49
- Zuletzt bearbeitet 08.09.2026 22:18:38
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields.
CVE-2026-19299
- EPSS 0.48%
- Veröffentlicht 04.09.2026 15:47:09
- Zuletzt bearbeitet 08.09.2026 22:21:17
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to path traversal.
CVE-2026-19302
- EPSS 0.48%
- Veröffentlicht 04.09.2026 15:41:40
- Zuletzt bearbeitet 08.09.2026 22:13:42
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.
CVE-2026-19304
- EPSS 0.31%
- Veröffentlicht 04.09.2026 15:30:25
- Zuletzt bearbeitet 28.09.2026 19:16:49
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information from internal services due to a URL parser discrepancy.
CVE-2026-19305
- EPSS 0.29%
- Veröffentlicht 04.09.2026 15:25:28
- Zuletzt bearbeitet 08.09.2026 22:06:27
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery.
CVE-2026-19306
- EPSS 0.41%
- Veröffentlicht 04.09.2026 15:20:47
- Zuletzt bearbeitet 08.09.2026 22:04:05
IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JWT signing keys, the application database, /proc/self/environ, and other tenant...
CVE-2026-9138
- EPSS 0.29%
- Veröffentlicht 04.09.2026 14:27:27
- Zuletzt bearbeitet 10.09.2026 21:17:53
IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write arbitrary files to the server due to improper input validation in the SaveToFileComponent. The application constructs local file paths using attacker‑contro...
CVE-2026-8447
- EPSS 0.18%
- Veröffentlicht 04.09.2026 14:27:03
- Zuletzt bearbeitet 08.09.2026 21:49:51
IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored cross-site scripting vulnerability in the Playground chat interface.
CVE-2026-9186
- EPSS 0.29%
- Veröffentlicht 04.09.2026 14:23:20
- Zuletzt bearbeitet 08.09.2026 21:45:27
IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 header, enabling arbitrary writes to IDE config files (~/.cursor/mcp.json, etc....