User Data Exposure and Deletion Vulnerability in IBM Langflow OSS
CVE-2026-6542

6.5MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
30 April 2026

What is CVE-2026-6542?

The vulnerability in IBM Langflow OSS versions 1.0.0 to 1.8.4 allows unauthorized users to supply their own flow_id, which may lead to the exposure of sensitive transaction logs and the ability to manipulate vertex build data that belongs to other users. This flaw enables users to delete persisted vertex build data for flows created by others, posing a significant risk to user privacy and data integrity.

Affected Version(s)

Langflow OSS 1.0.0 <= 1.8.4

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.