Back

CRITICAL

Unauthenticated Flow Execution via Webhook Endpoint in Langflow OSS

Published Jun 22, 2026

Description

IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.

Affected products

Remediation

Vendor solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.9.1 https://pypi.org/project/langflow/

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner ibm
Published Jun 22, 2026
Updated Jun 23, 2026
Reserved May 1, 2026

CISA Vulnrichment

Updated Jun 23, 2026

NVD

Status Analyzed
Modified Jun 26, 2026

Red Hat

No data

ENISA EUVD

Assigner ibm
Published Jun 22, 2026
Updated Jun 23, 2026

GitHub

No data