CVE-2026-9130: Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement

Published Aug 5, 2026
·
Updated

IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of other users via sessionid collision. The MemoryComponent.retrievemessages and storemessage methods filter on sessionid without validating flowid or userid ownership, enabling cross-user information disclosure through multiple authenticated API endpoints including /api/v1/run/, /api/v1/responses, and /api/v2/workflow/. This vulnerability only affects multi-user deployments with LANGFLOWAUTOLOGIN=False.

Other sources

Langflow OSS contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of other users via sessionid collision. The MemoryComponent.retrievemessages and storemessage methods filter on sessionid without validating flowid or userid ownership, enabling cross-user information disclosure through multiple authenticated API endpoints including /api/v1/run/, /api/v1/responses, and /api/v2/workflow/. This vulnerability only affects multi-user deployments with LANGFLOWAUTOLOGIN=False.

IBM

Affected Software

4 affected components
IBM Langflow OSS>=1.0.0<=1.10.3
IBM Langflow OSS
IBM Langflow OSS<=1.0.0-1.10.3
Langflow Langflow>=1.0.0<1.11.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade IBM Langflow OSS to a version that resolves this vulnerability.

    Fixed in 1.11.0
  2. Configuration

    This authorization bypass impacts multi-user deployments when LANGFLOW_AUTO_LOGIN=False; if feasible for your deployment model, set LANGFLOW_AUTO_LOGIN to True to avoid the affected condition.

    Langflow OSS LANGFLOW_AUTO_LOGIN = False
  3. Compensating control

    If you operate a multi-user deployment, limit authenticated users’ ability to access endpoints that can be used for cross-user disclosure (/api/v1/run/*, /api/v1/responses, /api/v2/workflow/*) by applying strict network/ACL/WAF rules so only authorized users can reach the relevant API endpoints.

Event History

Aug 5, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
CVE Published
via MITRE·06:16 PM
Data Sourced
via MITRE·06:16 PM
RemedyDescriptionSeverity
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeaknessAffected Software
May 23, 58572
Event
via FIRST·03:16 AM

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the severity of CVE-2026-9130?

CVE-2026-9130 has a severity rating of high with a score of 7.1.

2

What is CVE-2026-9130 about?

CVE-2026-9130 involves an authorization bypass vulnerability in IBM Langflow OSS that may allow authenticated users to access other users' chat histories.

3

How do I fix CVE-2026-9130?

To mitigate CVE-2026-9130, users should upgrade IBM Langflow OSS to a patched version beyond 1.10.3.

4

What components are affected by CVE-2026-9130?

The MemoryComponent of IBM Langflow OSS versions 1.0.0 through 1.10.3 is affected by CVE-2026-9130.

5

What types of attacks can CVE-2026-9130 facilitate?

CVE-2026-9130 can facilitate arbitrary code execution due to a failure in validating custom component inputs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203