What happened
IBM's security bulletin discloses that Langflow's public-flow security restrictions and session-isolation controls are not enforced on publicly shared MCP project endpoints, allowing an unauthenticated attacker to execute arbitrary code and access or modify other users' chat sessions. This is one of eight code-execution-related CVEs disclosed together (CWE-863 Incorrect Authorization), the highest-severity of the cluster at CVSS 9.8.
Why it matters
Langflow is a popular open-source visual builder for LLM/agent pipelines; unauthenticated RCE through a public-facing MCP integration point means any org that shares a Langflow flow publicly (a common pattern for demos/internal tooling) can be fully compromised and have live chat sessions from other users hijacked.
Attack vector
An unauthenticated attacker reaches a publicly shared MCP project endpoint; because the public-flow code-execution guard and session-namespace scoping enforced elsewhere are not applied to MCP Tools stdio components invoked via public flows, the attacker can execute arbitrary code and tamper with/access other users' chat sessions without authentication.
Affected systems
IBM Langflow OSS, versions 1.0.0 through 1.11.5
Mitigation
Apply IBM's Langflow security bulletin fixes; upgrade to the patched Langflow release covering CVE-2026-85025 (and the related cluster: CVE-2026-79724, CVE-2026-81941, CVE-2026-81204, CVE-2026-81211, CVE-2026-81940, CVE-2026-78569, CVE-2026-78575). Advisory: https://www.ibm.com/support/pages/node/7286666