CVE-2026-79723: Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-controlled API endpoints.
Other sources
Langflow OSS could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-controlled API endpoints.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Langflow OSSto a version that resolves this vulnerability.Fixed in 1.11.6
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker must be authenticated to exploit it. The vulnerability affects IBM Langflow OSS versions 1.0.0 through 1.11.5.
What access or capability does an attacker need?
The attacker needs a Langflow OSS account and the ability to supply user-controlled API endpoint URLs that the server will fetch. No user interaction is required.
What is the likely impact of successful exploitation?
Successful exploitation can allow an authenticated remote attacker to obtain sensitive information through server-side requests to improperly validated endpoints. The provided information indicates confidentiality impact only; integrity and availability impacts are not identified.