ZeroHour

CVE-2026-85025

moderate

Unauthenticated RCE and Session Exposure in IBM Langflow OSS Public MCP Endpoints

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

IBM Langflow OSS versions 1.0.0 through 1.11.5 contain an incorrect-authorization flaw (CWE-863): when a flow is shared publicly through its MCP (Model Context Protocol) project endpoints, the server fails to properly enforce public-flow security restrictions and per-session isolation. Because the required access controls are not correctly applied, an unauthenticated attacker can reach these publicly shared endpoints over the network with no credentials and no user interaction. Successful exploitation allows the attacker to execute arbitrary code on the Langflow server and to read or modify chat sessions belonging to the shared project, producing the high confidentiality, integrity, and availability impact reflected in the 9.8 CVSS score. Anyone running an affected Langflow OSS version with a publicly shared MCP project endpoint is exposed, while deployments that do not share flows publicly face materially lower risk. There is currently no known public proof-of-concept and no confirmed exploitation in the wild, and the issue is not yet listed in CISA's KEV catalog.

What to do: Upgrade Langflow OSS to a fixed release newer than 1.11.5 as soon as IBM publishes one, checking the IBM security advisory for the exact fixed version. Until patched, avoid sharing flows publicly via MCP project endpoints, or restrict network access to Langflow instances (internal-only binding, reverse proxy with authentication, or firewall rules) so the endpoints are not internet-reachable. Audit deployments for publicly shared flows and review affected chat sessions for signs of unauthorized access or modification.

Affected
IBM Langflow OSS1.0.0 through 1.11.5 (inclusive)
Estimated exposure
moderateseveral thousand internet-exposed Langflow OSS instances (subset of a larger self-hosted install base) — Langflow is a widely adopted open-source AI-agent builder typically self-hosted via Docker or pip, and public internet scans historically reveal on the order of thousands of exposed instances, of which only those running publicly shared…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow security restrictions and session isolation controls.

Vendors
langflow
Products
langflow
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.