PT-2026-66565 · Langflow+2 · Langflow+1

CVE-2026-13444

·

Published

2026-07-30

·

Updated

2026-08-04

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions IBM Langflow OSS versions 1.0.0 through 1.10.1
Description An attacker can access private vector documents belonging to another user by creating a flow that uses matching persist directory and collection name values. This allows the attacker to retrieve the victim's content in their own workflow output without authorization. Furthermore, the attacker can pollute the victim's collection by inserting their own documents into the shared namespace.
Recommendations Update IBM Langflow OSS to a version later than 1.10.1.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13444

Affected Products

Langflow
Langflow Oss