Description
IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations to IDE configuration files on the host system.
Published: 2026-08-05
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises when IBM Langflow OSS interprets untrusted input in its Model Context Protocol features, allowing hackers to circumvent localhost‑only restrictions. Remote authenticated attackers can use this flaw to write arbitrary MCP server configurations to IDE configuration files on the host. This can result in the execution of malicious code or other privilege‑escalating actions, effectively granting attackers full control of the system. The weakness is categorized as insecure permission checks (CWE‑807).

Affected Systems

IBM Langflow OSS versions 1.0.0 through 1.10.3 are affected. Earlier releases beyond 1.10.3 have been patched; no other IBM products or languages are impacted per the CNA data.

Risk and Exploitability

The flaw carries a high severity CVSS score of 8.5 and has no publicly available EPSS estimate. It does not appear on the CISA Known Exploited Vulnerabilities list, suggesting no large‑scale active exploitation. Attackers must be authenticated, but once logged in they can bypass the intended access controls and write configuration files across the network, providing a clear path to remote code execution. The lack of in‑depth monitoring or key restrictions makes exploitation straightforward for any compromised account.

Generated by OpenCVE AI on August 5, 2026 at 18:41 UTC.

Remediation

Vendor Solution

IBM recommends upgrading to Langflow OSS 1.11.0 or newer https://github.com/langflow-ai/langflow/releases


OpenCVE Recommended Actions

  • Upgrade IBM Langflow OSS to version 1.11.0 or later to apply the vendor‑issued fix.
  • If an immediate upgrade is not possible, isolate the MCP server configuration service to trusted local networks only and disable any remote write capabilities.
  • Implement strict authentication and authorization controls around configuration file modifications, ensuring that only local or explicitly authorized sessions can alter IDE configuration files.

Generated by OpenCVE AI on August 5, 2026 at 18:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations to IDE configuration files on the host system.
Title Reliance on Untrusted Inputs in a Security Decision vulnerabilities in Model Context Protocol features
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-807
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.10.3:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N'}


Subscriptions

Ibm Langflow Oss
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-05T18:11:44.684Z

Reserved: 2026-05-20T12:47:05.715Z

Link: CVE-2026-9077

cve-icon Vulnrichment

Updated: 2026-08-05T18:11:41.385Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T19:30:05Z

Weaknesses
  • CWE-807

    Reliance on Untrusted Inputs in a Security Decision