CVE-2026-7646: Langflow is affected by security vulnerabilities in Model Context Protocol features
IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other users' uploaded documents, the JWT signing secret, the SQLite database, and process environment variables, by sending a crafted MCP resources/read request with a URL-encoded path traversal sequence in the filename.
Other sources
Langflow OSS allows users to read arbitrary files from the server
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
langflow-ai/langflow (Langflow OSS)to a version that resolves this vulnerability.Fixed in 1.11.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7646?
The severity of CVE-2026-7646 is classified as medium with a score of 6.5.
How do I fix CVE-2026-7646?
To mitigate CVE-2026-7646, update IBM Langflow OSS to the latest version that addresses the vulnerability.
What type of vulnerabilities are associated with CVE-2026-7646?
CVE-2026-7646 is associated with path traversal and potential SQL injection vulnerabilities.
What can an attacker do with the vulnerabilities in CVE-2026-7646?
An attacker exploiting CVE-2026-7646 can read arbitrary files from the server filesystem, which may include sensitive data.
Which versions of IBM Langflow OSS are affected by CVE-2026-7646?
IBM Langflow OSS versions 1.0.0 through 1.10.3 are affected by CVE-2026-7646.