← Zurück zur CVE-Suche

CVE-2026-7663

IBM Langflow OSS

Beschreibung

IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.

CVSS 9.1EPSS 0.328%Risiko 0.94
Quelle öffnen
Veröffentlicht
2026-06-30 20:17:31
Betroffene Versionen
>=1.0.0,<1.9.7
Typ
Kritische Software
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N