CVE-2026-85025
moderateUnauthenticated RCE and Session Exposure in IBM Langflow OSS Public MCP Endpoints
IBM Langflow OSS versions 1.0.0 through 1.11.5 contain an incorrect-authorization flaw (CWE-863): when a flow is shared publicly through its MCP (Model Context Protocol) project endpoints, the server fails to properly enforce public-flow security restrictions and per-session isolation. Because the required access controls are not correctly applied, an unauthenticated attacker can reach these publicly shared endpoints over the network with no credentials and no user interaction. Successful exploitation allows the attacker to execute arbitrary code on the Langflow server and to read or modify chat sessions belonging to the shared project, producing the high confidentiality, integrity, and availability impact reflected in the 9.8 CVSS score. Anyone running an affected Langflow OSS version with a publicly shared MCP project endpoint is exposed, while deployments that do not share flows publicly face materially lower risk. There is currently no known public proof-of-concept and no confirmed exploitation in the wild, and the issue is not yet listed in CISA's KEV catalog.
What to do: Upgrade Langflow OSS to a fixed release newer than 1.11.5 as soon as IBM publishes one, checking the IBM security advisory for the exact fixed version. Until patched, avoid sharing flows publicly via MCP project endpoints, or restrict network access to Langflow instances (internal-only binding, reverse proxy with authentication, or firewall rules) so the endpoints are not internet-reachable. Audit deployments for publicly shared flows and review affected chat sessions for signs of unauthorized access or modification.
| IBM Langflow OSS | 1.0.0 through 1.11.5 (inclusive) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow security restrictions and session isolation controls.
- Vendors
- langflow
- Products
- langflow
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.