Impact
The vulnerability originates from improper cache key isolation in the MCP Tools component of Langflow OSS, allowing an authenticated attacker to access or modify another user's MCP server context. This bypass of access controls can expose sensitive data stored within the MCP feature, compromising confidentiality for multiple users in a shared environment. It does not enable arbitrary code execution or privilege escalation beyond the target user's context.
Affected Systems
Affected versions include IBM Langflow OSS 1.0.0 through 1.11.5. All installations utilizing the MCP Tools module are susceptible. Critical deployments using these releases should verify their current version and assess whether they employ MCP features that store user‑specific context.
Risk and Exploitability
The CVSS score of 4.2 represents moderate severity. Because no EPSS score is provided, exploitation probability is unknown, and the vulnerability is not in the CISA KEV catalog. Exploitation requires a valid authenticated session; once logged in, an attacker can request another user's MCP context through the component, but no additional privileges are gained. The lack of public exploitation evidence keeps overall risk moderate, yet the presence of this flaw warrants timely remediation.
OpenCVE Enrichment