CVE-2026-12763: IBM Langflow OSS vulnerability
Published Aug 28, 2026
·Updated
Langflow OSS could allow an authenticated attacker to access another user's MCP server context due to improper cache key isolation in the MCP Tools component
Affected Software
1 affected component
IBM Langflow OSS<=1.0.0-1.11.2
Event History
Aug 28, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
Which deployments should be prioritized for review?
Prioritize IBM Langflow OSS deployments that use the MCP Tools component, where cache key isolation can allow access across user MCP server contexts.
2
What access does an attacker need to exploit this issue?
The attacker must be authenticated to Langflow OSS.