CVE-2026-18904
moderateUnauthenticated IDOR in IBM Langflow OSS leaks data and allows message injection
IBM Langflow OSS versions 1.0.0 through 1.11.1 contain an authorization flaw (CWE-639, user-controlled key bypass) caused by a namespace collision between user identifiers. A remote, unauthenticated attacker can exploit this over the network by supplying or manipulating user identifiers that collide across namespaces. Successful exploitation allows the attacker to obtain sensitive information belonging to other users and to inject unauthorized messages. All deployments of Langflow OSS in the 1.0.0–1.11.1 range are affected, particularly multi-user or multi-tenant instances reachable over a network. No public proof-of-concept or confirmed in-the-wild exploitation is known, and EPSS currently estimates only a 0.3% probability of exploitation within 30 days.
What to do: Upgrade Langflow OSS to a release newer than 1.11.1 as soon as a patched version is published, and monitor IBM/PSIRT advisories for the fixed release. Until patched, avoid exposing Langflow directly to the internet and place it behind authentication or a reverse proxy. Operators of multi-user or multi-tenant deployments should review logs for cross-user data access or unexpected injected messages in flows and chats.
| IBM Langflow OSS | 1.0.0 through 1.11.1 (inclusive) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject unauthorized messages due to a namespace collision between user identifiers.
- Vendors
- langflow
- Products
- langflow
- Weakness
- CWE-639
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.