CVE 9.8 CRITICAL

Unauthenticated Flow Execution via Webhook Endpoint in Langflow OSS_CVE-2026-7664

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.

AI Analysis

Unauthenticated attackers can access protected MCP project resources and execute MCP operations due to improper authorization in the Streamable MCP transport endpoint.

Basic Information

ID CVE-2026-7664
Source ibm
Published Jun 22, 2026 at 14:10

Affected Product

Vendor IBM
Product Langflow OSS
Version 1.0.0
Affected Versions IBM Langflow OSS 1.0.0

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor IBM
Product Langflow OSS
Version 1.0.0-1.8.4

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.