Ibm Langflow Oss vulnerabilities
141 known vulnerabilities affecting ibm/langflow_oss.
Total CVEs
141
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL36HIGH73MEDIUM32
Vulnerabilities
Page 6 of 8
CVE-2026-19304P3HIGHCVSS 7.7≥ 1.0.0, ≤ 1.11.22026-09-04
CVE-2026-19304 [HIGH] CWE-918 CVE-2026-19304: IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitiv
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information from internal services due to a URL parser discrepancy.
nvd
CVE-2026-19305P3HIGHCVSS 7.5≥ 1.0.0, ≤ 1.11.22026-09-04
CVE-2026-19305 [HIGH] CWE-918 CVE-2026-19305: IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery.
nvd
CVE-2026-9081P3HIGHCVSS 7.1≥ 1.0.0, ≤ 1.10.32026-08-05
CVE-2026-9081 [HIGH] CWE-918 CVE-2026-9081: IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forge
IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the validate_model_provider_key() function for the Ollama provider. The function accepts a user-supplied OLLAMA_BASE_URL parameter and passes it directly to requests.get() without validation, scheme/host allowlisting, or filteri
nvd
CVE-2026-79725P3MEDIUMCVSS 6.5≥ 1.0.0, ≤ 1.11.52026-09-10
CVE-2026-79725 [MEDIUM] CWE-284 CVE-2026-79725: IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to read arbitrary
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to read arbitrary files due to improper access control.
nvd
CVE-2026-9225P3MEDIUMCVSS 6.5≥ 1.0.0, ≤ 1.11.52026-09-10
CVE-2026-9225 [MEDIUM] CWE-639 CVE-2026-9225: IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an authenticated attacker to access sensi
IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an authenticated attacker to access sensitive files belonging to other users due to improper access control in the File/Read File component. When executing flows through the /api/v1/run/advanced/{flow_id} endpoint, the application allows component inputs to reference storage paths using arbitr
nvd
CVE-2026-93677P3HIGHCVSS 7.7≥ 1.0.0, ≤ 1.12.22026-10-07
CVE-2026-93677 [HIGH] CWE-200 CVE-2026-93677: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitiv
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to exposure of sensitive information to an unauthorized actor.
nvd
CVE-2026-19300P3HIGHCVSS 7.5≥ 1.0.0, ≤ 1.11.22026-09-04
CVE-2026-19300 [HIGH] CWE-200 CVE-2026-19300: IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields.
nvd
CVE-2026-12945P3HIGHCVSS 7.1≥ 1.0.0, ≤ 1.10.12026-07-30
CVE-2026-12945 [HIGH] CWE-639 CVE-2026-12945: IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other user
IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on log retrieval and unauthenticated build endpoints.
nvd
CVE-2026-9130P3HIGHCVSS 7.1≥ 1.0.0, ≤ 1.10.32026-08-05
CVE-2026-9130 [HIGH] CWE-639 CVE-2026-9130: IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryCom
IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of other users via session_id collision. The MemoryComponent.retrieve_messages and store_message methods filter on session_id without validating flow_id or user_id ownership, enabling cross-use
nvd
CVE-2026-9186P3MEDIUMCVSS 6.5≥ 1.0.0, ≤ 1.11.22026-09-04
CVE-2026-9186 [MEDIUM] CWE-284 CVE-2026-9186: IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only
IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 header, enabling arbitrary writes to IDE config files (~/.cursor/mcp.json, etc.).
nvd
CVE-2026-14470P3MEDIUMCVSS 6.5≥ 1.0.0, ≤ 1.10.22026-09-04
CVE-2026-14470 [MEDIUM] CWE-22 CVE-2026-14470: IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to traverse directories
IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
nvd
CVE-2026-101331P3HIGHCVSS 7.7≥ 1.0.0, ≤ 1.12.22026-10-07
CVE-2026-101331 [HIGH] CWE-522 CVE-2026-101331: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitiv
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to insufficiently protected credentials.
nvd
CVE-2026-13442P3HIGHCVSS 7.1≥ 1.0.0, ≤ 1.10.12026-07-28
CVE-2026-13442 [HIGH] CWE-520 CVE-2026-13442: IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace
IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only vector content and influence later query results. This causes cross-user information disclosure and limited integrity impact through persistent poisoning of returned results.
nvd
CVE-2026-7658P3MEDIUMCVSS 6.5≥ 1.0.0, ≤ 1.10.32026-08-05
CVE-2026-7658 [MEDIUM] CWE-22 CVE-2026-7658: IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attack
IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path traversal sequences and bypass containment checks. This enables multiple severe impacts, including arbitrary directory deletion, cross-tenant data destruction, and JWT signing key deletion leading to session invalidation.
nvd
CVE-2026-93678P3HIGHCVSS 7.6≥ 1.0.0, ≤ 1.12.22026-10-07
CVE-2026-93678 [HIGH] CWE-639 CVE-2026-93678: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitiv
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper authorization.
nvd
CVE-2026-10128P3MEDIUMCVSS 6.5≥ 1.0.0, ≤ 1.10.32026-08-05
CVE-2026-10128 [MEDIUM] CWE-200 CVE-2026-10128: IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow com
IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbitrary server environment variables, exposing sensitive secrets despite security controls intended to disable custom components.
nvd
CVE-2026-7657P3MEDIUMCVSS 6.5≥ 1.0.0, ≤ 1.10.32026-08-05
CVE-2026-7657 [MEDIUM] CWE-918 CVE-2026-7657: IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to
IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplete and ineffective SSRF protection enforcement.
nvd
CVE-2026-7754P3MEDIUMCVSS 6.5≥ 1.0.0, ≤ 1.10.02026-07-17
CVE-2026-7754 [MEDIUM] CWE-918 CVE-2026-7754: IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF)
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure default configuration and incomplete enforcement of the SSRF protection mechanism.
nvd
CVE-2026-19294P3MEDIUMCVSS 6.5≥ 1.0.0, ≤ 1.11.12026-08-28
CVE-2026-19294 [MEDIUM] CWE-639 CVE-2026-19294: IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute and rea
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute and read any user's private flow due to improper authorization.
nvd
CVE-2026-12765P3MEDIUMCVSS 6.5≥ 1.0.0, ≤ 1.10.22026-09-14
CVE-2026-12765 [MEDIUM] CWE-918 CVE-2026-12765: IBM Langflow OSS 1.0.0 through 1.10.2 is vulnerable to server-side request forgery (SSRF). This may
IBM Langflow OSS 1.0.0 through 1.10.2 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
nvd