
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-85025 is a critical Incorrect Authorization vulnerability in IBM Langflow OSS that allows unauthenticated remote attackers to execute arbitrary code and access or modify chat sessions through publicly shared MCP (Model Context Protocol) project endpoints. It affects IBM Langflow OSS versions 1.0.0 through 1.11.5, with version 1.11.6 being the first patched release. The vulnerability was published on September 10, 2026, and carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, IBM Advisory).
The root cause is classified as CWE-863 (Incorrect Authorization), stemming from improper enforcement of public-flow security restrictions and inadequate session isolation controls within Langflow's MCP project endpoint handling. When a flow is shared publicly via an MCP project endpoint, the application fails to correctly enforce access boundaries, allowing unauthenticated actors to interact with the underlying execution engine and cross session boundaries. No authentication or user interaction is required, and the attack can be conducted entirely over the network with low complexity (GitHub Advisory, IBM Advisory).
Successful exploitation grants an unauthenticated attacker full remote code execution on the Langflow server, with high impact to confidentiality, integrity, and availability. Attackers can also access or modify other users' chat sessions, exposing potentially sensitive conversational data and AI workflow configurations. The combination of arbitrary code execution and session hijacking creates significant risk for lateral movement within the hosting environment and exposure of any data processed by the Langflow instance (GitHub Advisory, IBM Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit code and no confirmed evidence of in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment classifies the vulnerability as automatable with total technical impact, indicating that mass exploitation is theoretically feasible without manual intervention. The EPSS score is approximately 0.43%, placing it in the 36th percentile for exploitation likelihood within 30 days. No threat actor attribution or CISA KEV catalog listing has been reported at this time.
curl, wget, or scripting interpreters); unexpected network listeners created by the Langflow process.IBM has released a patch in Langflow OSS version 1.11.6, and all users running versions 1.0.0 through 1.11.5 should upgrade immediately (IBM Advisory). As an interim workaround, administrators should restrict network access to Langflow endpoints using firewalls or reverse proxy access controls, and review all MCP project sharing settings to ensure public endpoints are only exposed when strictly necessary. Access logs should be reviewed for unauthorized access attempts to shared project endpoints.
Security news outlets covered the vulnerability as part of a broader disclosure of multiple critical RCE flaws in IBM Langflow OSS, with at least one report referencing "12 critical RCE flaws" with CVSS scores of 9.8 (ThreatAft, UndercodeTesting). Social media activity on platforms including Mastodon and Bluesky noted the severity of the vulnerability shortly after disclosure. No formal public statement beyond the IBM advisory has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."