CVE-2026-13442
published 2026-07-28CVE-2026-13442: IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only vector content and influence later…
PriorityP340high7.1CVSS 3.1
AVNACLPRLUINSUCHILAN
EPSS
0.17%
7.0th percentile
IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only vector content and influence later query results. This causes cross-user information disclosure and limited integrity impact through persistent poisoning of returned results.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | langflow_oss | 1.0.0 – 1.10.1 | — |
| langflow | langflow | >= 1.0.0 < 1.10.2 | 1.10.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM Langflow OSS up to 1.10.1 information disclosure
vuldb·2026-07-28·CVSS 7.1
CVE-2026-13442 [HIGH] IBM Langflow OSS up to 1.10.1 information disclosure
A vulnerability classified as problematic was found in IBM Langflow OSS up to 1.10.1. The impacted element is an unknown function. The manipulation results in information disclosure.
This vulnerability is identified as CVE-2026-13442. The attack can be executed remotely. There is not any exploit available.
GHSA
IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only vector content and influence later query results.
ghsa_unreviewed·2026-07-28
CVE-2026-13442 [HIGH] CWE-520 IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only vector content and influence later query results.
IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only vector content and influence later query results. This causes cross-user information disclosure and limited integrity impact through persistent poisoning of returned results.
Suricata
ET WEB_SPECIFIC_APPS UTT formPdbUpConfig policyNames Parameter Command Injection Attempt (CVE-2025-13442, CVE-2026-2846)
suricata·2025-12-12·CVSS 6.9
CVE-2025-13442 [MEDIUM] ET WEB_SPECIFIC_APPS UTT formPdbUpConfig policyNames Parameter Command Injection Attempt (CVE-2025-13442, CVE-2026-2846)
ET WEB_SPECIFIC_APPS UTT formPdbUpConfig policyNames Parameter Command Injection Attempt (CVE-2025-13442, CVE-2026-2846)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS UTT formPdbUpConfig policyNames Parameter Command Injection Attempt (CVE-2025-13442, CVE-2026-2846)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:23; content:"/goform/formPdbUpConfig"; fast_pattern; http.request_body; content:"policyNames|3d|"; pcre:"/^[^\x26]*?(?:(?:\x3b|%3[Bb])|(?:\x0a|%0[Aa])|(?:\x60|%60)|(?:\x7c|%7[Cc])|(?:\x24|%24))+/R"; reference:url,github.com/alc9700jmo/CVE/issues/20; reference:cve,2025-13442; reference:cve,2026-2846; classtype:attempted-admin; sid:2066303; rev:1; metadata:affected_product UTT, attack_target Networking_Equipment, tls_state plaintext
No public exploits indexed.
No writeups or analysis indexed.
2026-07-28
Published