Back

MEDIUM

Langflow is vulnerable to stored cross-site scripting and IP spoofing due to unsanitized Markdown rendering and untrusted proxy header trust

Published Sep 4, 2026

Description

IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 header, enabling arbitrary writes to IDE config files (~/.cursor/mcp.json, etc.).

Affected products

Remediation

Vendor solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.11.3 https://pypi.org/project/langflow/

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner ibm
Published Sep 4, 2026
Updated Sep 8, 2026
Reserved May 21, 2026

CISA Vulnrichment

Updated Sep 8, 2026

NVD

Status Analyzed
Modified Sep 8, 2026

Red Hat

No data

ENISA EUVD

Assigner ibm
Published Sep 4, 2026
Updated Sep 8, 2026

GitHub

No data