IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on log retrieval and unauthenticated build endpoints.
Advisories
No advisories yet.
Fixes
Solution
IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.10.2 https://pypi.org/project/langflow/
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7279994 |
|
History
Thu, 30 Jul 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on log retrieval and unauthenticated build endpoints. | |
| Title | Langflow is affected by exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints | |
| First Time appeared |
Ibm
Ibm langflow Oss |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:langflow_oss:1.10.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm langflow Oss |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-07-30T16:44:39.380Z
Reserved: 2026-06-22T20:24:54.097Z
Link: CVE-2026-12945
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-30T19:45:06Z
Weaknesses