CyberRota Analysis
AI-GeneratedIBM Langflow OSS versions 1.0.0 to 1.11.5 are vulnerable to improper cache key isolation in the MCP Tools component, enabling authenticated attackers to access another user's MCP server context. This could lead to unauthorized data exposure and potential manipulation of user-specific information. Organizations utilizing affected versions should prioritize remediation to mitigate risks associated with this vulnerability.
CVE
CVE-2026-12763
Severity
MEDIUM
CVSS
4.2
EPSS
0.15%
Original NVD Description
IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context due to improper cache key isolation in the MCP Tools component.