Impact
The vulnerability originates component of Langflow OSS, allowing an authenticated attacker to access or modify another user's MCP server context. This (CWE‑306) bypass of access controls can expose sensitive data stored within the MCP feature, compromising confidentiality for multiple users in a shared environment. It does not enable arbitrary code execution or privilege escalation beyond the target user's context.
Affected Systems
Affected versions include IBM Langflow OSS 1.0.0 through 1.11.5. All installations utilizing the MCP Tools module are susceptible. Critical deployments using these releases should verify their current version and assess whether they employ MCP features that store user‑specific context.
Risk and Exploitability
The CVSS score of 4.2 represents moderate severity. The EPSS score indicates a very low exploitation probability (<1%), and the vulnerability is not in the CISA KEV catalog. Exploitation requires a valid authenticated session; once logged in, an attacker can request another user's MCP context through the component, but no additional privileges are gained. The lack of public exploitation evidence keeps overall risk moderate, yet the presence of this flaw warrants timely remediation.
OpenCVE Enrichment