CVE-2026-85025: Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards
IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow security restrictions and session isolation controls.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.11.6
Event History
Frequently Asked Questions
Which deployments are exposed to unauthenticated attack?
IBM Langflow OSS versions 1.0.0 through 1.11.5 are affected when publicly shared MCP project endpoints are available. The issue is reachable by an unauthenticated attacker over the network.
What access does an attacker need to exploit this issue?
No authentication, privileges, or user interaction are required. An attacker can exploit the affected publicly shared MCP project endpoints remotely with low attack complexity.
What could an attacker do after successful exploitation?
An attacker could execute arbitrary code and access or modify chat sessions. The reported impact includes high confidentiality, integrity, and availability impact.