CVE-2026-9077: Reliance on Untrusted Inputs in a Security Decision vulnerabilities in Model Context Protocol features
IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations to IDE configuration files on the host system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Langflow OSSto a version that resolves this vulnerability.Fixed in 1.11.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9077?
The severity of CVE-2026-9077 is rated high with a score of 8.5.
How do I fix CVE-2026-9077?
To mitigate CVE-2026-9077, update IBM Langflow OSS to a version later than 1.10.3 where the vulnerability is resolved.
What are the potential impacts of CVE-2026-9077?
CVE-2026-9077 allows remote authenticated attackers to bypass localhost-only restrictions and alter configurations on the host system.
Which versions of IBM Langflow OSS are affected by CVE-2026-9077?
IBM Langflow OSS versions 1.0.0 through 1.10.3 are affected by CVE-2026-9077.
Is remote access required to exploit CVE-2026-9077?
Yes, remote authenticated access is required to exploit CVE-2026-9077.