CyberRota Analysis
AI-GeneratedIBM Langflow OSS versions 1.0.0 through 1.10.3 are vulnerable to an authentication bypass through the Model Context Protocol (MCP) composer endpoint when the mcp_composer_enabled setting is true and projects use OAuth for authentication. This flaw could allow unauthorized access to sensitive data or functionalities, posing a significant risk to users relying on OAuth for secure access. Organizations utilizing affected versions should prioritize remediation to mitigate potential exploitation.
Original NVD Description
IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP) composer endpoint when mcp_composer_enabled=true (default) and projects are configured with auth_type=oauth .
Related CVEs
Other vulnerabilities affecting the same vendor(s)