SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-85025

CRITICAL · CVSS 9.8 EPSS 0.43%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

IBM Langflow OSS versions 1.0.0 to 1.11.5 are vulnerable to arbitrary code execution by unauthenticated attackers, who can exploit improperly enforced security restrictions to access or modify chat sessions via publicly shared MCP project endpoints. This critical vulnerability poses significant risks to any organization using affected versions, particularly those handling sensitive data or communications. Organizations leveraging Langflow should prioritize immediate patching or mitigation strategies to safeguard against potential exploitation.

CVE
CVE-2026-85025
Severity
CRITICAL
CVSS
9.8
EPSS
0.43%

Original NVD Description

IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow security restrictions and session isolation controls.