CVE-2026-7664: Unauthenticated Flow Execution via Webhook Endpoint in Langflow OSS
IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.
Other sources
Langflow OSS could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
langflowto a version that resolves this vulnerability.Fixed in 1.9.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7664?
CVE-2026-7664 has a critical severity score of 9.8.
How do I fix CVE-2026-7664?
To fix CVE-2026-7664, upgrade your IBM Langflow OSS to the latest version that addresses the vulnerability.
What impact does CVE-2026-7664 have on my system?
CVE-2026-7664 allows unauthenticated attackers to access protected resources and execute operations within IBM Langflow OSS.
Which versions of IBM Langflow OSS are affected by CVE-2026-7664?
IBM Langflow OSS versions 1.0.0 through 1.8.4 are affected by CVE-2026-7664.
What type of vulnerability is CVE-2026-7664?
CVE-2026-7664 is an unauthenticated flow execution vulnerability due to improper authorization enforcement.