Authenticated Access Vulnerability in IBM Langflow OSS Tools
CVE-2026-12763
4.2MEDIUM
What is CVE-2026-12763?
The vulnerability affects IBM Langflow OSS versions from 1.0.0 to 1.11.5, posing a risk where an authenticated attacker can exploit improper cache key isolation in the MCP Tools component. This flaw could potentially allow the attacker to access another user's MCP server context, leading to unauthorized disclosure of sensitive information. Immediate attention to patching and securing affected versions is recommended to mitigate risks.
Affected Version(s)
Langflow OSS 1.0.0 <= 1.11.5