Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-8505: IBM Langflow OSS: Unauthenticated users can trigger any flow
CVE-2026-8505
CVE-2026-8505
Summary
IBM Langflow OSS versions 1.0.0 through 1.10.0 have a security issue where anyone can trigger any flow without needing a password. This could allow an attacker to execute malicious code. To stay safe, update to the latest version of IBM Langflow OSS as soon as possible.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | langflow oss | <= 1.10.0 |
| langflow | langflow |
>= 1.0.0, < 1.10.1 cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* |
Original title
IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypass...
Original description
IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses API key validation when the WEBHOOK_AUTH_ENABLE configuration is set to False (which is the default setting). This allows a remote attacker who knows a flow's UUID to execute it as if they were the owner, potentially leading to Remote Code Execution (RCE).
nvd CVSS3.1
9.8
Vulnerability type
CWE-306
Missing Authentication for Critical Function
Published: 17 Jul 2026 · Updated: 20 Jul 2026 · First seen: 17 Jul 2026