Description
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject unauthorized messages due to a namespace collision between user identifiers.
Published: 2026-08-28
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Langflow OSS versions 1.0.0 through 1.11.1 contain a namespace collision flaw that can allow a remote attacker to bypass authentication, traverse directory paths, authorize unintended actions, and perform server‑side request forgery. The vulnerability can result in viewing sensitive data and injecting unauthorized messages, compromising the confidentiality and control of the application.

Affected Systems

User deployments of IBM Langflow OSS that are running any version from 1.0.0 up through and including 1.11.1 are affected. The recommended fixed release is Langflow OSS 1.11.2.

Risk and Exploitability

The flaw scores a CVSS of 8.2, indicating substantial impact. Because the EPSS is not published, exploitation likelihood is unknown, but the attack vector is clearly remote, requiring only access to the exposed web interface or API. The vulnerability is not listed in CISA’s KEV catalog, but the combined factors of authentication bypass and potential data leakage make it a high‑risk issue.

Generated by OpenCVE AI on August 29, 2026 at 00:04 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.11.2 https://pypi.org/project/langflow/


OpenCVE Recommended Actions

  • Upgrade IBM Langflow OSS to version 1.11.2 or later immediately.
  • Configure the application so that each user has a unique namespace prefix (e.g., include a project or tenant ID) to eliminate namespace collisions.
  • Disable or restrict the API endpoints that allow arbitrary message injection and sensitive data retrieval until the patch is deployed, and monitor for suspicious activity.

Generated by OpenCVE AI on August 29, 2026 at 00:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject unauthorized messages due to a namespace collision between user identifiers.
Title Langflow is affected by multiple authentication bypass, path traversal, authorization, and server-side request forgery vulnerabilities
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-639
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.11.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Ibm Langflow Oss
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-28T20:52:08.372Z

Reserved: 2026-08-04T20:18:20.138Z

Link: CVE-2026-18904

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T22:16:47.227

Modified: 2026-08-28T22:16:47.227

Link: CVE-2026-18904

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T00:15:06Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key