ZeroHour

CVE-2026-18904

moderate

Unauthenticated IDOR in IBM Langflow OSS leaks data and allows message injection

CVSS 3.1
8.2 high
EPSS
<1%p23
Published
()
Modified
AI analysis

IBM Langflow OSS versions 1.0.0 through 1.11.1 contain an authorization flaw (CWE-639, user-controlled key bypass) caused by a namespace collision between user identifiers. A remote, unauthenticated attacker can exploit this over the network by supplying or manipulating user identifiers that collide across namespaces. Successful exploitation allows the attacker to obtain sensitive information belonging to other users and to inject unauthorized messages. All deployments of Langflow OSS in the 1.0.0–1.11.1 range are affected, particularly multi-user or multi-tenant instances reachable over a network. No public proof-of-concept or confirmed in-the-wild exploitation is known, and EPSS currently estimates only a 0.3% probability of exploitation within 30 days.

What to do: Upgrade Langflow OSS to a release newer than 1.11.1 as soon as a patched version is published, and monitor IBM/PSIRT advisories for the fixed release. Until patched, avoid exposing Langflow directly to the internet and place it behind authentication or a reverse proxy. Operators of multi-user or multi-tenant deployments should review logs for cross-user data access or unexpected injected messages in flows and chats.

Affected
IBM Langflow OSS1.0.0 through 1.11.1 (inclusive)
Estimated exposure
moderate≈ a few thousand internet-exposed Langflow instances, with the total self-hosted installed base likely in the tens of thousands — Estimate based on public internet-exposure scans during earlier Langflow vulnerabilities (which found thousands of exposed instances) and Langflow's popularity as a self-hosted AI/agent prototyping tool that is most often run internally…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject unauthorized messages due to a namespace collision between user identifiers.

Vendors
langflow
Products
langflow
Weakness
CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.