Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-85025
Homebrew vulnerability analysis and mitigation

Overview

CVE-2026-85025 is a critical Incorrect Authorization vulnerability in IBM Langflow OSS that allows unauthenticated remote attackers to execute arbitrary code and access or modify chat sessions through publicly shared MCP (Model Context Protocol) project endpoints. It affects IBM Langflow OSS versions 1.0.0 through 1.11.5, with version 1.11.6 being the first patched release. The vulnerability was published on September 10, 2026, and carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, IBM Advisory).

Technical details

The root cause is classified as CWE-863 (Incorrect Authorization), stemming from improper enforcement of public-flow security restrictions and inadequate session isolation controls within Langflow's MCP project endpoint handling. When a flow is shared publicly via an MCP project endpoint, the application fails to correctly enforce access boundaries, allowing unauthenticated actors to interact with the underlying execution engine and cross session boundaries. No authentication or user interaction is required, and the attack can be conducted entirely over the network with low complexity (GitHub Advisory, IBM Advisory).

Impact

Successful exploitation grants an unauthenticated attacker full remote code execution on the Langflow server, with high impact to confidentiality, integrity, and availability. Attackers can also access or modify other users' chat sessions, exposing potentially sensitive conversational data and AI workflow configurations. The combination of arbitrary code execution and session hijacking creates significant risk for lateral movement within the hosting environment and exposure of any data processed by the Langflow instance (GitHub Advisory, IBM Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit code and no confirmed evidence of in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment classifies the vulnerability as automatable with total technical impact, indicating that mass exploitation is theoretically feasible without manual intervention. The EPSS score is approximately 0.43%, placing it in the 36th percentile for exploitation likelihood within 30 days. No threat actor attribution or CISA KEV catalog listing has been reported at this time.

Exploitation steps

  1. Reconnaissance: Identify internet-facing IBM Langflow OSS instances (versions 1.0.0–1.11.5) using search engines like Shodan or Censys, or by scanning for Langflow's default web interface port.
  2. Identify public MCP endpoints: Browse or enumerate publicly shared MCP project endpoints exposed by the target Langflow instance, which require no authentication by design.
  3. Exploit missing authorization: Craft requests to the public MCP project endpoint that invoke flow execution capabilities beyond the intended public scope, exploiting the improper enforcement of public-flow security restrictions.
  4. Execute arbitrary code: Leverage the lack of session isolation to inject malicious payloads into the flow execution context, achieving remote code execution on the underlying server.
  5. Access or modify chat sessions: Exploit the absent session isolation controls to read or tamper with other users' active chat sessions, exfiltrating conversation data or injecting malicious content (GitHub Advisory, IBM Advisory).

Indicators of compromise

  • Network: Unexpected or high-volume unauthenticated requests to publicly shared MCP project endpoints; outbound connections from the Langflow server process to unknown external IPs.
  • Logs: Access logs showing unauthenticated requests to MCP project endpoints with unusual payloads or parameters; errors related to session isolation or authorization failures in Langflow application logs.
  • Process: Unusual child processes spawned by the Langflow server process (e.g., shell commands, curl, wget, or scripting interpreters); unexpected network listeners created by the Langflow process.
  • File System: New or modified files in the Langflow installation directory, particularly scripts or binaries not part of the original installation; creation of cron jobs or scheduled tasks by the Langflow service account.

Mitigation and workarounds

IBM has released a patch in Langflow OSS version 1.11.6, and all users running versions 1.0.0 through 1.11.5 should upgrade immediately (IBM Advisory). As an interim workaround, administrators should restrict network access to Langflow endpoints using firewalls or reverse proxy access controls, and review all MCP project sharing settings to ensure public endpoints are only exposed when strictly necessary. Access logs should be reviewed for unauthorized access attempts to shared project endpoints.

Community reactions

Security news outlets covered the vulnerability as part of a broader disclosure of multiple critical RCE flaws in IBM Langflow OSS, with at least one report referencing "12 critical RCE flaws" with CVSS scores of 9.8 (ThreatAft, UndercodeTesting). Social media activity on platforms including Mastodon and Bluesky noted the severity of the vulnerability shortly after disclosure. No formal public statement beyond the IBM advisory has been identified.

Additional resources


SourceThis report was generated using AI

Related Homebrew vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-91782LOW1.9
  • NixOS logoNixOS
  • gcc10-binutils
NoNoSep 15, 2026
CVE-2026-91781LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 15, 2026
CVE-2026-91780LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-91779LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-90831LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management