Authorization Bypass in IBM Langflow OSS Affects User Data Security
CVE-2026-9130

7.1HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
5 August 2026

What is CVE-2026-9130?

IBM Langflow OSS versions 1.0.0 to 1.10.3 exhibit a flaw in the MemoryComponent, where authenticated users can exploit an authorization bypass vulnerability. This issue allows these users to retrieve and access the chat history of other users due to insufficient validation on session_id parameters in certain API endpoints. Specifically, the methods used for retrieving and storing messages fail to validate ownership of flow_id or user_id, enabling unauthorized data access. This vulnerability poses significant risks to user privacy and security in environments where multiple users are authenticated, particularly when LANGFLOW_AUTO_LOGIN is disabled.

Affected Version(s)

Langflow OSS 1.0.0 <= 1.10.3

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sergio Cabrera (ddlxstudio) https://github.com/nekros1xx
.