IBM Langflow OSS 1.0.0
IBM Langflow OSS can let someone without a login run code on the service and access or change chat sessions. The exposure occurs through publicly shared MCP project endpoints.
- Severity
- CriticalCVSS 3.1 · 9.8
- Fix
- Fixed in 1.11.6
- Affected versions
- 1.0.0 through 1.11.5
- Weakness
- CWE-863Incorrect Authorization
- Exploit likelihood
- 0.43% in 30 daysEPSS, higher than 36% of known flaws
- Affects
- Langflow OSS
- Exploited
- Not confirmedNo confirmation recorded
- CISA SSVC
- No known exploitationAutomatable: yes · Technical impact: total
- EU ID
- EUVD-2026-75748ENISA vulnerability database
How it works
- The affected setup uses a publicly shared MCP project endpoint.
- Langflow does not properly enforce its public-flow security restrictions or separate sessions there.
- An attacker without a login can then run code and access or modify chat sessions.
What to do
Check the installed Langflow OSS version and whether publicly shared MCP project endpoints are enabled. Compare both details with IBM's advisory.
Upgrade Langflow OSS to version 1.11.6, as IBM recommends. Confirm the installed version after updating.
Technical details
CVE-2026-85025 is an authorization flaw in IBM Langflow OSS. IBM rates it critical because exploitation requires no login and can affect confidentiality, integrity, and availability.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required None Attacker needs no account or login
- User interaction None No victim action needed
- Scope Unchanged Impact stays within the same security authority
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculatorReferences
- ibm.com · 7286666 vendor-advisory patch NVD
- tenable.com · CVE-2026-85025 third party advisory vdb entry
- cve.org · CVERecord vdb entry
- cvefeed.io · CVE-2026-85025 third party advisory vdb entry
- cveawg.mitre.org · CVE-2026-85025