PT-2026-65596 · Langflow+2 · Langflow+1

CVE-2026-13442

·

Published

2026-07-28

·

Updated

2026-08-04

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions IBM Langflow OSS versions 1.0.0 through 1.10.1
Description An issue exists where an attacker can reuse another user's FAISS (Facebook AI Similarity Search, a library for efficient similarity search and clustering of dense vectors) namespace. This allows unauthorized access to vector content intended only for the owner and enables the attacker to influence subsequent query results, leading to cross-user information disclosure and persistent poisoning of returned results.
Recommendations Update IBM Langflow OSS to a version later than 1.10.1.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13442

Affected Products

Langflow
Langflow Oss