Back

HIGH

Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement

Published Aug 5, 2026

Description

IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of other users via session_id collision. The MemoryComponent.retrieve_messages and store_message methods filter on session_id without validating flow_id or user_id ownership, enabling cross-user information disclosure through multiple authenticated API endpoints including /api/v1/run/*, /api/v1/responses, and /api/v2/workflow/*. This vulnerability only affects multi-user deployments with LANGFLOW_AUTO_LOGIN=False.

Affected products

Remediation

Vendor solution

IBM recommends upgrading to Langflow OSS 1.11.0 or newer https://github.com/langflow-ai/langflow/releases

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published Aug 5, 2026
Updated Aug 7, 2026
Reserved May 20, 2026
CISA Vulnrichment
Updated Aug 5, 2026
NVD
Status Modified
Modified Aug 7, 2026
Red Hat
Severity n/a
Public date n/a