Description
IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only vector content and influence later query results. This causes cross-user information disclosure and limited integrity impact through persistent poisoning of returned results.
Published: 2026-07-28
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Langflow OSS contains a permission flaw that lets an attacker reuse another user’s FAISS namespace. This flaw can expose private vector data and allow the attacker to manipulate future query results. The impact is therefore primarily confidentiality loss for other users and a moderate integrity issue through persistent poisoning of returned results.

Affected Systems

The vulnerability is present in IBM Langflow OSS version 1.0.0 through 1.10.1. These versions expose unauthenticated and insufficiently authorized API endpoints that enable the impersonation scenario described.

Risk and Exploitability

The CVSS base score of 7.1 indicates a high severity, yet the EPSS score of less than 1 % shows a very low exploitation probability at present. The flaw is not listed in the CISA KEV catalog. It is likely exploited via network traffic that targets the exposed API endpoints, with no special privilege required. Attackers can send crafted requests to reference another user’s vector namespace, read private data, and inject poisoned vectors into the query pipeline.

Generated by OpenCVE AI on August 3, 2026 at 14:13 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.10.2 https://pypi.org/project/langflow/


OpenCVE Recommended Actions

  • Upgrade IBM Langflow OSS to version 1.10.2 or later
  • Ensure that all API endpoints accessing FAISS namespaces enforce proper authentication and authorization controls to prevent impersonation
  • Implement network segmentation or firewall rules to restrict external access to Langflow services and monitor for suspicious request patterns

Generated by OpenCVE AI on August 3, 2026 at 14:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only vector content and influence later query results. This causes cross-user information disclosure and limited integrity impact through persistent poisoning of returned results.
Title Langflow is affected by NET Misconfiguration: Use of Impersonation due to multiple unauthenticated and insufficiently authorized API endpoints
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-520
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.10.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Ibm Langflow Oss
Langflow Langflow
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-29T14:11:30.129Z

Reserved: 2026-06-26T16:32:33.209Z

Link: CVE-2026-13442

cve-icon Vulnrichment

Updated: 2026-07-29T14:11:24.287Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-28T21:17:25.387

Modified: 2026-08-04T20:11:02.010

Link: CVE-2026-13442

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T14:15:05Z

Weaknesses
  • CWE-520

    .NET Misconfiguration: Use of Impersonation