AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-10547

MEDIUM · CVSS 5.9 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

IBM Langflow OSS versions 1.0.0 through 1.10.3 are vulnerable due to inadequate validation of ownership in the deprecated POST /api/v1/build/{flow_id}/vertices endpoint, enabling authenticated users to inject arbitrary graph data into a shared cache. This flaw could lead to cross-user cache pollution, unauthorized execution of workflows, or potential denial of service. Organizations using affected versions should prioritize remediation to mitigate risks associated with unauthorized data manipulation and service disruption.

CVE
CVE-2026-10547
Severity
MEDIUM
CVSS
5.9
EPSS
0.22%

Original NVD Description

IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/vertices endpoint, allowing an authenticated user to inject arbitrary graph data into a shared cache for any flow. This may result in cross-user cache pollution, unauthorized workflow execution, or denial of service.

Related CVEs

Other vulnerabilities affecting the same vendor(s)