CVE-2026-9130
published 2026-08-05CVE-2026-9130: IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat…
PriorityP340high7.1CVSS 3.1
AVNACLPRLUINSUCHILAN
EPSS
0.18%
7.2th percentile
IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of other users via session_id collision. The MemoryComponent.retrieve_messages and store_message methods filter on session_id without validating flow_id or user_id ownership, enabling cross-user information disclosure through multiple authenticated API endpoints including /api/v1/run/*, /api/v1/responses, and /api/v2/workflow/*. This vulnerability only affects multi-user deployments with LANGFLOW_AUTO_LOGIN=False.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | langflow_oss | 1.0.0 – 1.10.3 | — |
| langflow | langflow | >= 1.0.0 < 1.11.0 | 1.11.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM Langflow OSS up to 1.10.3 MemoryComponent session_id authorization
vuldb·2026-08-05·CVSS 7.1
CVE-2026-9130 [HIGH] IBM Langflow OSS up to 1.10.3 MemoryComponent session_id authorization
A vulnerability classified as problematic has been found in IBM Langflow OSS up to 1.10.3. This issue affects the function MemoryComponent.retrieve_messages/ MemoryComponent.store_message of the component MemoryComponent. The manipulation of the argument session_id leads to authorization bypass.
This vulnerability is uniquely identified as CVE-2026-9130. The attack is possible to be carried out remotely. No exploit exists.
GHSA
IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of other users via session_id collisio
ghsa_unreviewed·2026-08-05
CVE-2026-9130 [HIGH] IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of other users via session_id collisio
IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of other users via session_id collision. The MemoryComponent.retrieve_messages and store_message methods filter on session_id without validating flow_id or user_id ownership, enabling cross-user information disclosure through multiple authenticated API endpoints including /api/v1/run/*, /api/v1/responses, and /api/v2/workflow/*. This vulnerability only affects multi-user deployments with LANGFLOW_AUTO_LOGIN=False.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-05
Published