Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-85025: Langflow allows remote code execution and chat tampering
CVE-2026-85025 · published 15 days ago
Summary
Versions 1.0.0 through 1.11.5 of the Langflow open source project let anyone on the internet run their own code on the server and change or view chat sessions that are shared publicly. This happens because the software does not properly check who can access public workflow endpoints or keep separate sessions isolated. Update to a patched version or restrict access to the endpoints until a fix is applied.
What to do
- Update langflow langflow to version 1.11.6 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | langflow oss | <= 1.11.5 |
| langflow | langflow |
>= 1.0.0, < 1.11.6 cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* |
Original advisory text
IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due...
IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow security restrictions and session isolation controls.
References
- https://www.ibm.com/support/pages/node/7286666 Vendor Advisory
Severity
9.8
Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-863Incorrect Authorization
Timeline
Published10 Sep 2026
Updated25 Sep 2026
First seen10 Sep 2026
Track software like this
Free during beta