logo

Critical Security Flaws Found in Langflow OSS

ID: 3c4bee56-0666-51c3-9c4e-ea436f81f8d9

STIX ID: report--3c4bee56-0666-51c3-9c4e-ea436f81f8d9

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-07-04

Date Updated: 2026-08-06

Author: Do Son

...
...

IBM Security disclosed six severe vulnerabilities in Langflow OSS — including an unauthenticated RCE (CVE-2026-10134), validation bypass (CVE-2026-7803), insecure deserialization in Redis (CVE-2026-7871), code injection via code validation (CVE-2026-7873), and authorization flaws causing cross-tenant API key reuse and MCP ownership bypass (CVE-2026-10140, CVE-2026-7663). Researchers validated multiple PoC scenarios (notably MCP bypasses); no active exploitation in the wild was confirmed. Administrators are urged to upgrade to Langflow 1.10.1 (or at least 1.10.0 for some fixes) and restart processes to clear cached API keys.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.