CVE-2026-81213
moderateUnauthenticated SSRF in IBM Langflow OSS 1.0.0–1.11.5
IBM Langflow OSS versions 1.0.0 through 1.11.5 improperly validate user-supplied URLs, creating a server-side request forgery flaw (CWE-918). A remote, unauthenticated attacker can supply a crafted URL that causes the Langflow server to issue requests to attacker-chosen targets, including resources on the internal network, with no user interaction required. The attacker gains access to sensitive information returned by those internal requests, producing high confidentiality impact, while integrity and availability are unaffected. Anyone running Langflow OSS 1.0.0 through 1.11.5 is affected, with the greatest risk for instances exposed to the internet or placed where they can reach internal or cloud-metadata services. No public proof-of-concept, CISA KEV listing, or known exploitation in the wild has been reported.
What to do: Upgrade Langflow OSS to the latest release beyond 1.11.5 per IBM's advisory (a fixed version number is not specified in the available data). Until patched, restrict the Langflow host's outbound network access — e.g., block access to cloud metadata endpoints and internal-only services — and avoid exposing Langflow directly to the internet. Review web and egress logs for unexpected outbound HTTP requests originating from Langflow servers.
| IBM Langflow OSS | 1.0.0 through 1.11.5 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of user-supplied URLs.
- Vendors
- langflow
- Products
- langflow
- Weakness
- CWE-918
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.