Description
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information or inject malicious data due to improper access control in the vertex result caching subsystem.
Published: 2026-10-06
Score: 8.3 High
EPSS: n/a
KEV: No
Impact: Information disclosure and data injection by authenticated remote attacker
Action: Immediate Patch
AI Analysis

Impact

IBM Langflow OSS versions 1.0.0 through 1.12.2 contain an improper access control flaw in the vertex result caching subsystem, classified as CWE-284. The flaw permits a remote attacker who has authenticated to the application to read sensitive information that is cached or to inject malicious data into the cache. This could lead to disclosure of confidential data or the execution of unintended operations within the application.

Affected Systems

All publicly available builds of IBM Langflow OSS from version 1.0.0 up to and including 1.12.2 are affected. The vulnerability is specific to the vertex result caching component within the Langflow OSS code base. No later releases beyond 1.12.2 are known to contain the flaw.

Risk and Exploitability

With a CVSS score of 8.3, the vulnerability is considered high severity. The EPSS score is not available, so there is no current estimate of how frequently this vulnerability is being exploited in the wild. Because the flaw requires an authenticated session, an attacker must first gain legitimate credentials before exploiting the weakness. The vulnerability is not currently listed in the CISA KEV catalog. Given the high CVSS score and the authentication requirement, the risk of exploitation is moderate to high for organizations that maintain user access to Langflow OSS.

Generated by OpenCVE AI on October 7, 2026 at 01:39 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.12.3. https://pypi.org/project/langflow/#description


OpenCVE Recommended Actions

  • Upgrade IBM Langflow OSS to version 1.12.3 or later.
  • If an upgrade is not immediately possible, restrict access to the vertex result caching subsystem through network segmentation or stricter authentication controls to eliminate improper access.
  • Configure monitoring of cache access logs to detect unauthorized read or write operations.

Generated by OpenCVE AI on October 7, 2026 at 01:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 00:30:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information or inject malicious data due to improper access control in the vertex result caching subsystem.
Title Langflow OSS is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-284
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'}


Subscriptions

Ibm Langflow Oss
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-06T23:59:21.197Z

Reserved: 2026-09-24T20:51:09.395Z

Link: CVE-2026-97680

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T01:16:36.780

Modified: 2026-10-07T01:16:36.780

Link: CVE-2026-97680

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T01:45:08Z

Weaknesses