๐Ÿ” CVE Alert

CVE-2026-13444

HIGH 8.1

Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents by creating their own flow with matching Chroma persist_directory and collection_name values. The attacker receives exact victim content in their workflow output despite having no authorization to read the victim's flow. Additionally, the attacker can pollute the victim's collection by inserting their own documents into the shared namespace.

CWE CWE-520
Vendor ibm
Product langflow oss
Published Jul 30, 2026
Last Updated Jul 30, 2026
Stay Ahead of the Next One

Get instant alerts for ibm langflow oss

Be the first to know when new high vulnerabilities affecting ibm langflow oss are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

IBM / Langflow OSS
1.0.0 โ‰ค 1.10.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
ibm.com: https://www.ibm.com/support/pages/node/7279989