Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-8505: IBM Langflow OSS: Unauthenticated users can trigger any flow

CVE-2026-8505 CVE-2026-8505
Summary

IBM Langflow OSS versions 1.0.0 through 1.10.0 have a security issue where anyone can trigger any flow without needing a password. This could allow an attacker to execute malicious code. To stay safe, update to the latest version of IBM Langflow OSS as soon as possible.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
ibm langflow oss <= 1.10.0
langflow langflow >= 1.0.0, < 1.10.1
cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*
Original title
IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypass...
Original description
IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses API key validation when the WEBHOOK_AUTH_ENABLE configuration is set to False (which is the default setting). This allows a remote attacker who knows a flow's UUID to execute it as if they were the owner, potentially leading to Remote Code Execution (RCE).
nvd CVSS3.1 9.8
Vulnerability type
CWE-306 Missing Authentication for Critical Function
Published: 17 Jul 2026 · Updated: 20 Jul 2026 · First seen: 17 Jul 2026