← Volver al buscador de CVEs

CVE-2026-7663

IBM Langflow OSS

Descripción

IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.

CVSS 9.1EPSS 0.328%Riesgo 0.94
Ver fuente
Publicación
2026-06-30 20:17:31
Versiones afectadas
>=1.0.0,<1.9.7
Tipo
Software crítico
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N