AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-9077

HIGH · CVSS 8.5 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

IBM Langflow versions 1.0.0 to 1.10.3 are vulnerable to a remote authenticated attack that allows bypassing localhost-only restrictions, enabling attackers to write arbitrary MCP server configurations to IDE configuration files on the host system. This could lead to unauthorized access and manipulation of the system's configuration, potentially compromising its integrity and security. Organizations using affected versions should prioritize patching this vulnerability to mitigate the risk of exploitation.

CVE
CVE-2026-9077
Severity
HIGH
CVSS
8.5
EPSS
0.31%

Original NVD Description

IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations to IDE configuration files on the host system.

Related CVEs

Other vulnerabilities affecting the same vendor(s)