CVE-2026-13442: Langflow is affected by NET Misconfiguration: Use of Impersonation due to multiple unauthenticated and insufficiently authorized API endpoints
IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only vector content and influence later query results. This causes cross-user information disclosure and limited integrity impact through persistent poisoning of returned results.
Other sources
Langflow OSS can allow an attacker to reuse another user's FAISS namespace to access owner-only vector content and influence later query results. This causes cross-user information disclosure and limited integrity impact through persistent poisoning of returned results.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.10.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13442?
CVE-2026-13442 has a severity score of 7.1, indicating it's a high-risk vulnerability.
How do I fix CVE-2026-13442?
To mitigate CVE-2026-13442, ensure all API endpoints are authenticated and that proper authorization checks are implemented.
What systems are affected by CVE-2026-13442?
CVE-2026-13442 affects IBM Langflow OSS versions 1.0.0 through 1.10.1.
What impact does CVE-2026-13442 have?
CVE-2026-13442 allows attackers to access owner-only vector content leading to information disclosure and potential query result manipulation.
Who is vulnerable to CVE-2026-13442?
Any user of IBM Langflow OSS versions 1.0.0 through 1.10.1 is at risk of being affected by CVE-2026-13442.