PT-2026-60839 · Ibm · Langflow Oss
CVE-2026-9103
·
Published
2026-07-17
·
Updated
2026-09-05
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Langflow OSS versions 1.0.0 through 1.10.0
Description
Improper authentication in the '/api/v1/login/auto login' endpoint allows remote attackers to gain unauthorized administrative access. When the
AUTO LOGIN configuration is enabled, which is the default setting, the endpoint issues long-lived superuser bearer tokens without requiring authentication. Furthermore, permissive Cross-Origin Resource Sharing (CORS)—a mechanism that allows restricted resources on a web page to be requested from another domain—may expose these tokens to unintended origins.Recommendations
Disable the
AUTO LOGIN configuration for versions 1.0.0 through 1.10.0 to prevent the issuance of unauthenticated superuser tokens.Fix
DoS
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Langflow Oss