CVE-2026-13442
IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only vector content and influence later query results. This causes cross-user information disclosure and limited integrity impact through persistent poisoning of returned results.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- EPSS probability
- 0.17%
- CWE
- CWE-520
- Published
- 2026-07-28
- Last modified
- 2026-07-29
Affected products
- IBM Langflow OSS
Weakness type
Related vulnerabilities
- CVE-2026-13444 — Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
- CVE-2026-2450 — .NET misconfiguration: use of impersonation vulnerability in upKeeper Solutions upKeeper Instant...
- CVE-2019-25608 — Iperius Backup 6.1.0 Privilege Escalation via Backup Job