CVE-2026-85025
IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow security restrictions and session isolation controls.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-863
- Published
- 2026-09-10
- Last modified
- 2026-09-10
Affected products
- IBM Langflow OSS
Weakness type
Related vulnerabilities
- CVE-2026-89151 — Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow...
- CVE-2026-78134 — strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins...
- CVE-2026-81905 — Concrete CMS below 9.5.3 does not enforce validation-hash type on redemption, allowing a hash issued for one purpose to be redeemed for another.
- CVE-2026-75624 — IBM App Connect Enterprise is vulnerable to privilege escalation and Denial of Service
- CVE-2026-87107 — Consul vulnerable to an authorization bypass in the catalog deregistration path
- CVE-2026-87090 — Consul vulnerable to an authorization bypass in the catalog node-write path
- CVE-2026-88044 — rclone: RC per-server auth-proxy bypass
- CVE-2026-88939 — knowns through 0.33.0 Authorization Bypass via project.set Bootstrap Exemption