Description
IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow security restrictions and session isolation controls.
Published: 2026-09-10
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

IBM Langflow OSS versions 1.0.0 through 1.11.5 contain a flaw that lets an unauthenticated attacker execute arbitrary code and alter or retrieve chat session data via publicly shared MCP project endpoints. The vulnerability stems from insufficient enforcement of public‑flow security restrictions and inadequate isolation of user sessions, allowing an attacker to inject code that runs within the application environment. This can lead to full compromise of the affected system, including data exfiltration, persistence, and further lateral movement.

Affected Systems

IBM Langflow OSS is the affected product, specifically versions 1.0.0 up to and including 1.11.5. The issue applies to installations that expose MCP project endpoints publicly, which are commonly used to share flow definitions with other users.

Risk and Exploitability

The CVSS score of 9.8 classifies this flaw as critical, indicating a high likelihood of a successful attack if the vulnerability is exploited. While the EPSS score is not available, the absence of a KEV listing does not diminish the potential for exploitation; many similar remote code execution flaws are actively targeted in the wild. The attacker can reach the vulnerable endpoint over the network without authentication, making the attack surface broad and the risk for any exposed deployment significant. Prompt remediation is strongly advised to mitigate both confidentiality, integrity, and availability risks.

Generated by OpenCVE AI on September 11, 2026 at 04:50 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.11.6 https://pypi.org/project/langflow/


OpenCVE Recommended Actions

  • Apply IBM’s recommended patch to upgrade IBM Langflow OSS to version 1.11.6.
  • Re‑configure the application to enforce strict access controls on public‑flow endpoints and prevent unauthorized code execution.
  • Review session management settings to ensure proper isolation of chat sessions and eliminate cross‑session data exposure.

Generated by OpenCVE AI on September 11, 2026 at 04:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Langflow
Langflow langflow
CPEs cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*
Vendors & Products Langflow
Langflow langflow

Fri, 11 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow security restrictions and session isolation controls.
Title Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-863
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.11.5:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Langflow Oss
Langflow Langflow
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-12T03:55:25.053Z

Reserved: 2026-09-02T19:57:50.612Z

Link: CVE-2026-85025

cve-icon Vulnrichment

Updated: 2026-09-11T13:39:20.850Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T21:17:51.990

Modified: 2026-09-15T17:19:17.853

Link: CVE-2026-85025

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T08:30:11Z

Weaknesses