CVE-2026-12945

HIGH

Langflow is affected by exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints

Title source: cna
STIX 2.1

Description

IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on log retrieval and unauthenticated build endpoints.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory patch
https://www.ibm.com/support/pages/node/7279994

Scores

CVSS v3 7.1
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

Details

CWE
CWE-639
Status published
Products (1)
IBM/Langflow OSS 1.0.0 - 1.10.1
Published Jul 30, 2026
Tracked Since Jul 30, 2026