CVE-2026-6542: Monitor API allows cross-user read of transaction logs and deletion of build data via flow_id
IBM Langflow OSS 1.0.0 through 1.8.4 could allow any user to supply a flowid to read transaction logs and vertex build data belonging to other users, and to delete persisted vertex build data for another user's flow.
Other sources
Langflow OSS could allow any user to supply a flowid to read transaction logs and vertex build data belonging to other users, and to delete persisted vertex build data for another user's flow.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.9.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6542?
CVE-2026-6542 is considered a critical vulnerability due to its ability to allow unauthorized access to sensitive user data.
How do I fix CVE-2026-6542?
To fix CVE-2026-6542, update IBM Langflow OSS to version 1.8.5 or later to patch the vulnerability.
What type of vulnerability is CVE-2026-6542?
CVE-2026-6542 is a cross-user information disclosure vulnerability affecting the monitor API in IBM Langflow OSS.
Who is affected by CVE-2026-6542?
Users of IBM Langflow OSS versions 1.0.0 through 1.8.4 are affected by CVE-2026-6542.
Can CVE-2026-6542 be exploited remotely?
Yes, CVE-2026-6542 can be exploited remotely by any user who supplies a valid flow_id.