CVE-2026-17630: Langflow is affected by security vulnerabilities in Model Context Protocol features
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper validation of configuration parameters.
Other sources
Langflow OSS could allow a remote attacker to execute arbitrary code due to improper validation of configuration parameters.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.11.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-17630?
CVE-2026-17630 has a severity rating of 7.2, classified as high.
How do I fix CVE-2026-17630?
To fix CVE-2026-17630, update IBM Langflow to the latest version that addresses the improper validation of configuration parameters.
What systems are affected by CVE-2026-17630?
CVE-2026-17630 affects IBM Langflow OSS versions 1.0.0 through 1.10.3.
What types of attacks are possible with CVE-2026-17630?
CVE-2026-17630 could allow remote attackers to execute arbitrary code due to the security vulnerability.
When was CVE-2026-17630 published?
CVE-2026-17630 was published on August 5, 2026.