ZeroHour

CVE-2026-7663

CVSS 3.1
9.8 critical
EPSS
<1%p43
Published
()
Modified
Description

IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.

Vendors
langflow
Products
langflow
Weakness
CWE-285, CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.