Unauthenticated Session History Access via Public Flow Execution
CVE-2026-7787
7.5HIGH
What is CVE-2026-7787?
IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information by bypassing authentication using insecure direct object references.
Affected Version(s)
Langflow OSS 1.0.0 <= 1.9.1