CVE-2026-7872

HIGH

IBM Langflow OSS 1.0.0-1.10.0 - File Read and JWT Token Forgery

Title source: manual
STIX 2.1

Description

IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication tokens for any user.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory patch
https://www.ibm.com/support/pages/node/7278934

Scores

CVSS v3 7.5
EPSS 0.0036
EPSS Percentile 29.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
IBM/Langflow OSS 1.0.0 - 1.10.0
langflow/langflow 1.0.0 - 1.10.1
Published Jul 17, 2026
Tracked Since Jul 18, 2026