SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-13442

HIGH · CVSS 7.1 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-28 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

IBM Langflow OSS versions 1.0.0 to 1.10.1 are vulnerable to an issue that allows attackers to exploit another user's FAISS namespace, leading to unauthorized access to owner-only vector content. This vulnerability can result in cross-user information disclosure and the potential for persistent poisoning of query results, impacting data integrity. Organizations using affected versions should prioritize remediation to protect sensitive information and maintain data integrity.

CVE
CVE-2026-13442
Severity
HIGH
CVSS
7.1
EPSS
0.17%

Original NVD Description

IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only vector content and influence later query results. This causes cross-user information disclosure and limited integrity impact through persistent poisoning of returned results.

Related CVEs

Other vulnerabilities affecting the same vendor(s)