User Data Exposure and Deletion Vulnerability in IBM Langflow OSS
CVE-2026-6542
6.5MEDIUM
What is CVE-2026-6542?
The vulnerability in IBM Langflow OSS versions 1.0.0 to 1.8.4 allows unauthorized users to supply their own flow_id, which may lead to the exposure of sensitive transaction logs and the ability to manipulate vertex build data that belongs to other users. This flaw enables users to delete persisted vertex build data for flows created by others, posing a significant risk to user privacy and data integrity.
Affected Version(s)
Langflow OSS 1.0.0 <= 1.8.4