Vulnerability  ·  2026-09-11

IBM Langflow OSS — unauthenticated RCE and session hijack via publicly shared MCP project endpoints

VulnerabilityHigh impactGlobalCVE-2026-85025
IBM's security bulletin discloses that Langflow's public-flow security restrictions and session-isolation controls are not enforced on publicly shared MCP project endpoints, allowing an unauthenticated attacker to execute arbitrary code and access or modify other users' chat sessions. This is one of eight code-execution-related CVEs disclosed together (CWE-863 Incorrect Authorization), the highest-severity of the cluster at CVSS 9.8.
Langflow is a popular open-source visual builder for LLM/agent pipelines; unauthenticated RCE through a public-facing MCP integration point means any org that shares a Langflow flow publicly (a common pattern for demos/internal tooling) can be fully compromised and have live chat sessions from other users hijacked.
An unauthenticated attacker reaches a publicly shared MCP project endpoint; because the public-flow code-execution guard and session-namespace scoping enforced elsewhere are not applied to MCP Tools stdio components invoked via public flows, the attacker can execute arbitrary code and tamper with/access other users' chat sessions without authentication.
IBM Langflow OSS, versions 1.0.0 through 1.11.5
Apply IBM's Langflow security bulletin fixes; upgrade to the patched Langflow release covering CVE-2026-85025 (and the related cluster: CVE-2026-79724, CVE-2026-81941, CVE-2026-81204, CVE-2026-81211, CVE-2026-81940, CVE-2026-78569, CVE-2026-78575). Advisory: https://www.ibm.com/support/pages/node/7286666
IBM Security Bulletin - LangflowNVD - CVE-2026-85025
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →