ZeroHour

CVE-2026-81213

moderate

Unauthenticated SSRF in IBM Langflow OSS 1.0.0–1.11.5

CVSS 3.1
8.6 high
EPSS
Published
()
Modified
AI analysis

IBM Langflow OSS versions 1.0.0 through 1.11.5 improperly validate user-supplied URLs, creating a server-side request forgery flaw (CWE-918). A remote, unauthenticated attacker can supply a crafted URL that causes the Langflow server to issue requests to attacker-chosen targets, including resources on the internal network, with no user interaction required. The attacker gains access to sensitive information returned by those internal requests, producing high confidentiality impact, while integrity and availability are unaffected. Anyone running Langflow OSS 1.0.0 through 1.11.5 is affected, with the greatest risk for instances exposed to the internet or placed where they can reach internal or cloud-metadata services. No public proof-of-concept, CISA KEV listing, or known exploitation in the wild has been reported.

What to do: Upgrade Langflow OSS to the latest release beyond 1.11.5 per IBM's advisory (a fixed version number is not specified in the available data). Until patched, restrict the Langflow host's outbound network access — e.g., block access to cloud metadata endpoints and internal-only services — and avoid exposing Langflow directly to the internet. Review web and egress logs for unexpected outbound HTTP requests originating from Langflow servers.

Affected
IBM Langflow OSS1.0.0 through 1.11.5
Estimated exposure
moderatetens of thousands of users/deployments, of which likely low thousands to tens of thousands are internet-exposed instances — Langflow is a widely used open-source visual framework for building LLM/agent workflows, but most adoption is developer and internal self-hosted deployments (Docker, local, or intranet), with public internet scans historically finding only…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of user-supplied URLs.

Vendors
langflow
Products
langflow
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.