CVE-2026-17627: Langflow is affected by improper authorization due to missing access control on the voice-mode WebSocket endpoint
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information and inject messages into workflow history due to improper authorization.
Other sources
Langflow OSS could allow a remote authenticated attacker to obtain sensitive information and inject messages into workflow history due to improper authorization.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Langflow OSSto a version that resolves this vulnerability.Fixed in 1.10.3 - Configuration
Add/enable access control on the voice-mode WebSocket endpoint to prevent remote authenticated attackers from obtaining sensitive information and injecting messages into workflow history.
Langflow voice-mode WebSocket endpoint access control / authorization = enabled
Event History
Frequently Asked Questions
Does exploitation require valid credentials or user interaction?
Exploitation requires an authenticated remote attacker with low privileges. No user interaction is required, and the attack complexity is rated high.
Which deployments should be prioritized for remediation?
IBM Langflow OSS versions 1.0.0 through 1.10.2 are identified as affected. The issue may expose sensitive information and allow injection of messages into workflow history.