Critical Security Flaws Found in Langflow OSS
ID: 3c4bee56-0666-51c3-9c4e-ea436f81f8d9
STIX ID: report--3c4bee56-0666-51c3-9c4e-ea436f81f8d9
Feed Name: securityonline.info
IBM Security disclosed six severe vulnerabilities in Langflow OSS — including an unauthenticated RCE (CVE-2026-10134), validation bypass (CVE-2026-7803), insecure deserialization in Redis (CVE-2026-7871), code injection via code validation (CVE-2026-7873), and authorization flaws causing cross-tenant API key reuse and MCP ownership bypass (CVE-2026-10140, CVE-2026-7663). Researchers validated multiple PoC scenarios (notably MCP bypasses); no active exploitation in the wild was confirmed. Administrators are urged to upgrade to Langflow 1.10.1 (or at least 1.10.0 for some fixes) and restart processes to clear cached API keys.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
