AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-17626

HIGH · CVSS 8.8 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Docker-based MCP servers running IBM Langflow OSS versions 1.0.0 to 1.10.3 are vulnerable to exploitation by authenticated attackers, who can read, modify, or expose sensitive host files due to inadequate filtering of Docker volume-mount and device-mapping arguments. Organizations utilizing these versions should prioritize patching to mitigate the risk of data exposure and potential system compromise. Security teams and system administrators managing Docker environments should take immediate action to address this vulnerability.

CVE
CVE-2026-17626
Severity
HIGH
CVSS
8.8
EPSS
0.29%
Docker

Original NVD Description

IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Docker-based MCP servers due to incomplete filtering of dangerous Docker volume-mount and device-mapping arguments.

Related CVEs

Other vulnerabilities affecting the same vendor(s)