Server-Side Request Forgery Vulnerability in IBM Langflow
CVE-2026-7657
6.5MEDIUM
What is CVE-2026-7657?
The vulnerability in IBM Langflow arises from incomplete and ineffective enforcement of server-side request forgery (SSRF) protections. This flaw may allow attackers to manipulate requests to the backend server, potentially leading to unauthorized access to sensitive data and resources. Users of Langflow OSS from version 1.0.0 through 1.10.3 are at risk and should consider applying the recommended patches to mitigate exposure.
Affected Version(s)
Langflow OSS 1.0.0 <= 1.10.3