CVE-2026-81213: Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of user-supplied URLs.
Other sources
Langflow OSS could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of user-supplied URLs.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.11.6
Event History
Frequently Asked Questions
Which deployments are affected?
IBM Langflow OSS versions 1.0.0 through 1.11.5 are affected.
Does an attacker need credentials or user interaction to exploit this issue?
No. The supplied vector indicates network-based exploitation with low complexity, no privileges, and no user interaction required.
What could an attacker access through this vulnerability?
A remote attacker could obtain sensitive information from internal network resources by supplying URLs that are fetched server-side.