Vulnerability  ·  2026-09-15

IBM Langflow OSS — cross-user MCP Tools context leakage via improper cache-key isolation

VulnerabilityMedium impactGlobalCVE-2026-12763
Langflow is a widely used low-code platform for building LLM/agent workflows; cross-user MCP context leakage in a multi-tenant deployment exposes one user's connected-tool session and potentially credentials/data to another authenticated user — a meaningful confidentiality break in shared Langflow instances.
Improper cache-key isolation in the MCP Tools component allows an authenticated attacker to access another user's MCP server context — i.e., session/tool state belonging to a different user is retrievable due to shared/collision-prone cache keys.
IBM Langflow OSS 1.0.0 – 1.11.5
Consult IBM's support bulletin for the fixed version and upgrade path; restrict multi-tenant Langflow deployments until patched.
IBM Support BulletinNVD CVE-2026-12763
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →