Impact
Based on the description, it is inferred that attackers can reach the Streamable MCP transport endpoint over the network. IBM Langflow OSS versions 1.0.0 to 1.9.6 contain a flaw that allows unauthenticated users to gain unauthorized access to other users' MCP project resources and trigger MCP operations. The weakness is an improper authorization enforcement in the Streamable MCP transport endpoint, classified as CWE‑285 and CWE‑863. Successful exploitation results in confidentiality and integrity compromise of protected resources and execution of privileged operations.
Affected Systems
The affected software is IBM Langflow OSS, originally released in version 1.0.0 and all releases up to, and including, 1.9.6. Users are advised to check the semantic versioning of installed packages to determine whether they fall within the vulnerable range.
Risk and Exploitability
Based on the description, it is inferred that attackers can reach the Streamable MCP transport endpoint over the network, so the vulnerability is exploitable by anyone with network access to the service. The vulnerability carries a CVSS score of 9.1, indicating critical severity. The EPSS score is 0.00328, which is less than 1% and suggests a very low, yet non‑zero, probability of exploitation. Despite the low EPSS, the combination of high severity and external accessibility demands immediate remediation.
OpenCVE Enrichment