CVE-2026-81265
largeUnauthenticated SSRF in IBM Langflow OSS 1.0.0 through 1.11.5
CVE-2026-81265 is a server-side request forgery (SSRF, CWE-918) vulnerability in IBM Langflow OSS, the open-source visual builder for LLM and agent workflows, affecting versions 1.0.0 through 1.11.5. Per the CVSS vector, it is reachable over the network by an unauthenticated attacker with no user interaction, allowing them to induce the Langflow server to issue requests to attacker-chosen targets such as internal services or cloud metadata endpoints. The attacker gains read access to internal data (high confidentiality impact), but the flaw does not by itself permit code execution or data modification. Any self-hosted Langflow OSS deployment in the affected version range is affected, particularly instances reachable from untrusted networks or the internet. No public proof-of-concept or in-the-wild exploitation is currently known, and the issue is not listed in CISA KEV.
What to do: Upgrade Langflow OSS to the latest release newer than 1.11.5 as directed by IBM's advisory. Until patched, avoid exposing Langflow (default port 7860) directly to the internet, place it behind a VPN or an authenticating reverse proxy, and restrict the Langflow host's outbound access to cloud metadata endpoints (169.254.169.254) and internal network ranges to blunt SSRF abuse. Review server logs for unexpected outbound HTTP requests originating from the Langflow instance.
| IBM Langflow OSS | 1.0.0 through 1.11.5 (inclusive) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM Langflow OSS 1.0.0 through 1.11.5.
- Vendors
- langflow
- Products
- langflow
- Weakness
- CWE-918
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.