ZeroHour

Vulnerabilities

145 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-85025
+2 in the same advisory: …84889 …9225
Unauthenticated RCE and Session Exposure in IBM Langflow OSS Public MCP Endpoints

IBM Langflow OSS versions 1.0.0 through 1.11.5 contain an incorrect-authorization flaw (CWE-863): when a flow is shared publicly through its MCP (Model Context Protocol) project endpoints, the server fails to properly enforce public-flow security restrictions and per-session isolation. Because the required access controls are not correctly applied, an unauthenticated attacker can reach these publicly shared endpoints over the network with no credentials and no user interaction. Successful exploitation allows the attacker to execute arbitrary code on the Langflow server and to read or modify chat sessions belonging to the shared project, producing the high confidentiality, integrity, and availability impact reflected in the 9.8 CVSS score. Anyone running an affected Langflow OSS version with a publicly shared MCP project endpoint is exposed, while deployments that do not share flows publicly face materially lower risk. There is currently no known public proof-of-concept and no confirmed exploitation in the wild, and the issue is not yet listed in CISA's KEV catalog.

Do: Upgrade Langflow OSS to a fixed release newer than 1.11.5 as soon as IBM publishes one, checking the IBM security advisory for the exact fixed version. Until patched, avoid sharing flows publicly via MCP project endpoints, or restrict network access to Langflow instances (internal-only binding, reverse proxy with authentication, or firewall rules) so the endpoints are not internet-reachable. Audit deployments for publicly shared flows and review affected chat sessions for signs of unauthorized access or modification.

9.8
group max
  • IBM Langflow OSS 1.0.0 through 1.11.5 (inclusive)
moderateseveral thousand internet-exposed Langflow OSS instances (subset of a larger self-hosted install base)
CVE-2026-19298
Authenticated RCE via authorization bypass in IBM Langflow OSS 1.0.0–1.11.2

IBM Langflow OSS versions 1.0.0 through 1.11.2 contain an authorization bypass (code injection, CWE-94) in the flow build process, allowing attackers to execute arbitrary code. The flaw is triggered remotely by any attacker holding valid low-privilege credentials, who sends crafted requests to the flow build process where insufficient authorization checks permit injected code to run. Successful exploitation yields arbitrary code execution on the server with the service's privileges, with high impact to confidentiality, integrity, and availability (CVSS 3.1: 8.8). Any organization running Langflow OSS 1.0.0–1.11.2 is affected, particularly self-hosted instances exposed to the internet. There is no known exploitation in the wild, no public proof-of-concept, and a low predicted exploitation probability (EPSS 0.5%), and the issue is not in CISA's KEV catalog.

Do: Upgrade Langflow OSS from the affected 1.0.0–1.11.2 range to a fixed release newer than 1.11.2, checking IBM's and Langflow's advisories for the exact fixed version. Until upgraded, avoid exposing Langflow to the public internet, restrict which accounts hold credentials, and review access to the flow build endpoint. Defenders can confirm their deployed version and whether instances are internet-exposed.

8.8
group max
<1%
  • IBM Langflow OSS 1.0.0 through 1.11.2 (inclusive)
moderateon the order of 10,000–100,000 self-hosted instances/deployments worldwide
CVE-2026-19295
Authenticated OS command injection in IBM Langflow OSS

IBM Langflow OSS 1.0.0 through 1.11.1 contains a command/code injection flaw (CWE-95) in which a user-supplied 'type' field value in a saved flow is not neutralized when it is used during a flow build. An authenticated user can save a flow with a crafted type field value and then trigger a build of a wrapper flow that references it, causing the server process to execute attacker-controlled operating system commands. This escalates privileges from a restricted 'authenticated flow user' to arbitrary OS-level command execution running under the Langflow server process identity, and it works even when administrators have disabled custom components via LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false. Any deployment running the affected versions is exposed, with the greatest risk where untrusted users can create or edit flows or where the server is network-reachable. Exploitation has not been observed: there is no public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS currently gives it a 1% probability of exploitation in the next 30 days.

Do: Upgrade all Langflow OSS instances in the 1.0.0-1.11.1 range to the first patched release after 1.11.1, per IBM's advisory. Until patched, restrict who can save or create flows to trusted users and avoid exposing the server to the internet, and note that setting LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false does not prevent this flaw. Audit saved flows for unexpected 'type' field values and review what privileges the Langflow service account holds on the host.

9.9
group max
<1%
  • IBM Langflow OSS 1.0.0 through 1.11.1 (inclusive)
largetens of thousands of deployments (roughly 1k-10k directly internet-exposed)
CVE-2026-19875
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email information and abuse the server as an outbound relay due t

IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email information and abuse the server as an outbound relay due to missing authentication for the registration endpoint.

NVD description · AI analysis pending
7.5<1%
  • langflow langflow
CVE-2026-19297
IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authe

IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts.

NVD description · AI analysis pending
9.1<1%
  • langflow langflow
CVE-2026-9205
IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.

IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.

NVD description · AI analysis pending
9.8
group max
<1%
  • langflow langflow