CVE-2026-19875: Unauthenticated Registration POST Endpoint Permits Admin Email Overwrite and Outbound Relay Abuse in Langflow
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email information and abuse the server as an outbound relay due to missing authentication for the registration endpoint.
Other sources
Langflow OSS could allow a remote attacker to overwrite administrator email information and abuse the server as an outbound relay due to missing authentication for the registration endpoint.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Langflow OSSto a version that resolves this vulnerability.Fixed in 1.10.1
Event History
Frequently Asked Questions
Which deployments are exposed?
IBM Langflow OSS versions 1.0.0 through 1.10.0 are identified as affected. The issue is reachable remotely through the registration endpoint because that endpoint lacks authentication.
What can an unauthenticated attacker do?
A remote attacker can overwrite administrator email information and abuse the affected server as an outbound relay. No prior privileges or user interaction are required according to the supplied severity vector.
How can I determine whether my instance is affected?
Verify whether the deployment is IBM Langflow OSS and whether its version falls between 1.0.0 and 1.10.0. Also assess whether the registration endpoint is exposed, as the reported issue involves missing authentication on that endpoint.