ZeroHour

CVE-2026-17627

large

Improper Authorization in IBM Langflow OSS Leaks and Corrupts Workflow History

CVSS 3.1
7.1 high
EPSS
<1%p10
Published
()
Modified
AI analysis

IBM Langflow OSS versions 1.0.0 through 1.10.2 contain an improper authorization flaw (CWE-639) in which the application fails to correctly verify a user's permission to access specific workflow resources. A remote attacker with any valid low-privileged account can send crafted network requests to bypass the missing authorization checks. Successful exploitation allows the attacker to read sensitive information and inject attacker-controlled messages into workflow history, with no impact on availability. All Langflow OSS deployments running 1.0.0 through 1.10.2 are affected, though the requirement for an authenticated account reduces exposure for instances with a small user base. There is currently no known public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only about a 0.2% probability of exploitation in the next 30 days.

What to do: Upgrade Langflow to a fixed release newer than 1.10.2, following IBM's advisory for the exact patched version. Until patched, limit which accounts can reach the Langflow service, restrict its network exposure, and audit workflow history for unexpected or injected messages. Because exploitation requires valid credentials, also review and revoke unused or over-privileged accounts.

Affected
IBM Langflow OSS1.0.0 through 1.10.2 (inclusive)
Estimated exposure
large≈10,000–100,000 self-hosted deployments (exact install count unknown) — The estimate is based on Langflow's broad adoption as a popular open-source LLM/agent workflow builder, which is typically self-hosted by development teams and enterprises, with only a subset of instances exposed beyond their internal user…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information and inject messages into workflow history due to improper authorization.

Vendors
langflow
Products
langflow
Weakness
CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.