CVE-2026-12945
HIGHLangflow is affected by exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
Title source: cnaDescription
IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on log retrieval and unauthenticated build endpoints.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
patch
https://www.ibm.com/support/pages/node/7279994
Scores
CVSS v3
7.1
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
Details
CWE
CWE-639
Status
published
Products (1)
IBM/Langflow OSS
1.0.0 - 1.10.1
Published
Jul 30, 2026
Tracked Since
Jul 30, 2026