Improper Authorization Vulnerability in IBM Langflow OSS
CVE-2026-7663
9.1CRITICAL
What is CVE-2026-7663?
IBM Langflow OSS versions 1.0.0 through 1.9.6 are susceptible to a vulnerability that allows unauthenticated attackers to gain access to restricted MCP project resources and perform MCP operations. This issue arises from inadequate authorization checks in the Streamable MCP transport endpoint, creating potential security risks for organizations using this software.
Affected Version(s)
Langflow OSS 1.0.0 <= 1.9.6