SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-9186

MEDIUM · CVSS 6.5 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

IBM Langflow OSS versions 1.0.0 to 1.11.2 are vulnerable to a remote authenticated attack that allows adversaries to bypass localhost-only MCP configuration by spoofing the X-Forwarded-For header. This vulnerability enables unauthorized arbitrary writes to critical IDE configuration files, potentially compromising system integrity. Organizations using affected versions should prioritize remediation to safeguard their configurations from exploitation.

CVE
CVE-2026-9186
Severity
MEDIUM
CVSS
6.5
EPSS
0.27%

Original NVD Description

IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 header, enabling arbitrary writes to IDE config files (~/.cursor/mcp.json, etc.).

Related CVEs

Other vulnerabilities affecting the same vendor(s)