IBM
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any IBM product.
RSS Feeds for IBM security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in IBM products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by IBM Sorted by Most Security Vulnerabilities since 2018
Known Exploited IBM Vulnerabilities
The following IBM vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| IBM Langflow Code Injection Vulnerability |
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. CVE-2026-9198 |
August 4, 2026 |
| IBM Aspera Faspex Code Execution Vulnerability |
IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw. CVE-2022-47986 Exploit Probability: 100.0% |
February 21, 2023 |
| IBM InfoSphere BigInsights Invalid Input Vulnerability |
Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data. CVE-2013-3993 Exploit Probability: 5.2% |
May 25, 2022 |
| IBM WebSphere Application Server and Server Hypervisor Edition Code Injection. |
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands CVE-2015-7450 Exploit Probability: 97.7% |
January 10, 2022 |
| IBM Data Risk Manager Arbritary File Download |
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to download arbitrary files from the system. IBM X-Force ID: 180535. CVE-2020-4430 Exploit Probability: 68.5% |
November 3, 2021 |
| IBM Data Risk Manager Authentication Bypass |
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. IBM X-Force ID: 180532. CVE-2020-4427 Exploit Probability: 70.0% |
November 3, 2021 |
| IBM Data Risk Manager Command Injection |
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-Force ID: 180533. CVE-2020-4428 Exploit Probability: 61.7% |
November 3, 2021 |
| IBM Planning Analytics configuration overwrite vulnerability |
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094. CVE-2019-4716 Exploit Probability: 86.4% |
November 3, 2021 |
Of the known exploited vulnerabilities above, 6 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings.
By the Year
In 2026 there have been 476 vulnerabilities in IBM with an average score of 6.6 out of ten. Last year, in 2025 IBM had 563 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in IBM in 2026 could surpass last years number. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.37.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 476 | 6.62 |
| 2025 | 563 | 6.26 |
| 2024 | 503 | 6.44 |
| 2023 | 357 | 6.80 |
| 2022 | 327 | 6.36 |
| 2021 | 443 | 6.10 |
| 2020 | 353 | 6.19 |
| 2019 | 454 | 6.14 |
| 2018 | 451 | 6.24 |
It may take a day or so for new IBM vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent IBM Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-17624 | Aug 05, 2026 |
IBM Langflow OSS RCE via Improper Import Validation (pre-1.10.3)IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of module imports. |
|
| CVE-2026-17633 | Aug 05, 2026 |
Remote Code Exec via Code Injection in IBM Langflow OSS 1.0.0-1.10.3IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injection. |
|
| CVE-2026-17632 | Aug 05, 2026 |
IBM Langflow 1.0.0-1.10.3 RAA Exec via AST Validation FlawIBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code during AST-based security scanning. |
|
| CVE-2026-9196 | Aug 05, 2026 |
IBM Langflow OSS 1.0.0-1.10.3 Auth Exec via LLMgenerated Python ValidationIBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to improper handling of LLMgenerated components. The application executes modelgenerated Python code in the backend during validation prior to user approval, which may allow an attacker to trigger side effects such as outbound network access, file system interaction, or data exfiltration with the privileges of the Langflow backend process. |
|
| CVE-2026-8182 | Aug 05, 2026 |
Arbitrary Code Execution in IBM Langflow OSS 1.0.0-1.10.3 via 2 HTTP RqsIBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any credentials via 2 HTTP requests. |
|
| CVE-2026-9201 | Aug 05, 2026 |
IBM Langflow 1.0.0-1.10.3: Truncated SHA256 Authenticated Code ExecIBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in the custom component validation mechanism. When the optional hardening mode that restricts execution to trusted component templates is enabled, the application validates component code using a truncated SHA256 hash. Because the hash comparison relies on only a portion of the digest, an attacker can craft malicious component code that collides with a trusted template hash and bypasses validation. Successful exploitation allows the attacker to introduce and execute unauthorized Python code within the Langflow process, defeating the intended security control and potentially leading to full compromise of the affected instance. |
|
| CVE-2026-8478 | Aug 05, 2026 |
IBM Langflow OSS 1.0.0-1.10.3 RCE via Improper Input ControlIBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code. |
|
| CVE-2026-8183 | Aug 05, 2026 |
IBM Langflow OSS 1.0.0-1.10.3 URL DIRTRAVIBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to v i ew arbitrary files on the system. |
|
| CVE-2026-7658 | Aug 05, 2026 |
IBM Langflow OSS 1.0.01.10.3 Path Traversal via Username: Arbitrary DeletionIBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path traversal sequences and bypass containment checks. This enables multiple severe impacts, including arbitrary directory deletion, cross-tenant data destruction, and JWT signing key deletion leading to session invalidation. |
|
| CVE-2026-9130 | Aug 05, 2026 |
IBM Langflow OSS <1.10.3: MemoryComponent Auth Bypass & Cross-User DisclosureIBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of other users via session_id collision. The MemoryComponent.retrieve_messages and store_message methods filter on session_id without validating flow_id or user_id ownership, enabling cross-user information disclosure through multiple authenticated API endpoints including /api/v1/run/*, /api/v1/responses, and /api/v2/workflow/*. This vulnerability only affects multi-user deployments with LANGFLOW_AUTO_LOGIN=False. |
|
| CVE-2026-10547 | Aug 05, 2026 |
IBM Langflow 1.0.0-1.10.3 POST /api/v1/build/{flow_id}/vertices OW Validation LeakIBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/vertices endpoint, allowing an authenticated user to inject arbitrary graph data into a shared cache for any flow. This may result in cross-user cache pollution, unauthorized workflow execution, or denial of service. |
|
| CVE-2026-7869 | Aug 05, 2026 |
Path Traversal IBM Langflow OSS 1.0.01.10.3 KB APIIBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledge_bases`). This occurs because user-supplied knowledge base names are used directly to create file paths without proper sanitization or containment checks. An authenticated attacker can exploit this flaw to create directories and write files anywhere on the server's filesystem. |
|
| CVE-2026-8470 | Aug 05, 2026 |
IBM Langflow OSS 1.10.3: Fernet Key Gen Flaw via Python MT PRNGIBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under 32 characters. The deterministic Mersenne Twister PRNG produces identical keys for identical seeds, allowing attackers to reproduce encryption keys and decrypt stored API keys and authentication tokens. |
|
| CVE-2026-9205 | Aug 05, 2026 |
IBM Langflow OSS Weak Crypto Key Derivation in ensure_fernet_key()IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function. |
|
| CVE-2026-10128 | Aug 05, 2026 |
Auth env var exposure via IBM Langflow OSS <1.10.3 componentIBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbitrary server environment variables, exposing sensitive secrets despite security controls intended to disable custom components. |
|
| CVE-2026-9081 | Aug 05, 2026 |
IBM Langflow OSS 1.10.3 SSRF via OLLAMA_BASE_URLIBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the validate_model_provider_key() function for the Ollama provider. The function accepts a user-supplied OLLAMA_BASE_URL parameter and passes it directly to requests.get() without validation, scheme/host allowlisting, or filtering of private IP ranges (loopback, RFC1918, link-local addresses). |
|
| CVE-2026-7657 | Aug 05, 2026 |
IBM Langflow OSS 1.0.0-1.10.3 SSRF via incomplete protectionIBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplete and ineffective SSRF protection enforcement. |
|
| CVE-2026-17625 | Aug 05, 2026 |
IBM Langflow OSS <=1.10.3 Cmd Exec via OS Command injectionIBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. |
|
| CVE-2026-17623 | Aug 05, 2026 |
IBM Langflow OSS 1.0-1.10.3 MCP cmd exec (auth)IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of the command field in MCP server configurations. |
|
| CVE-2026-17630 | Aug 05, 2026 |
IBM Langflow OSS 1.0.0-1.10.3 RCE via improperly validated configIBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper validation of configuration parameters. |
|
| CVE-2026-17626 | Aug 05, 2026 |
IBM Langflow OSS 1.0.01.10.3: Authenticated Docker Volume-Mount DisclosureIBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Docker-based MCP servers due to incomplete filtering of dangerous Docker volume-mount and device-mapping arguments. |
|
| CVE-2026-8446 | Aug 05, 2026 |
IBM Langflow OSS 1.0.01.10.3 Auth Bypass via MCP composer endpoint (default enabled)IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP) composer endpoint when mcp_composer_enabled=true (default) and projects are configured with auth_type=oauth . |
|
| CVE-2026-7646 | Aug 05, 2026 |
IBM Langflow OSS <1.10.3 Arbitrary File Read via Res/Read Path TrvIBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other users' uploaded documents, the JWT signing secret, the SQLite database, and process environment variables, by sending a crafted MCP `resources/read` request with a URL-encoded path traversal sequence in the filename. |
|
| CVE-2026-9077 | Aug 05, 2026 |
IBM Langflow OSS Auth Bypass, pre-1.10.4 allows config file writeIBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations to IDE configuration files on the host system. |
|
| CVE-2026-17617 | Aug 05, 2026 |
IBM AppGW Operator 22.2-26.06 SSRF via Unvalidated URLsIBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources. |
|
| CVE-2026-15656 | Aug 05, 2026 |
IBM Maximo App Suite 9.x Cookie Secure Flag Not Set (CVE-2026-15656)IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. |
|
| CVE-2026-18531 | Aug 05, 2026 |
Weak HMAC Session Signing in IBM Maximo App Suite 9.2 allows tamperingIBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use of a weak HMAC session signing secret. |
|
| CVE-2026-10025 | Aug 05, 2026 |
IBM QRadar 7.5-7.6 XXE via q1labs_core.jar (before 7.6.2)IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use XML-format property autodetection, the system processes XML-formatted syslog events sent to port 514 (UDP/TCP) without authentication. |
|
| CVE-2026-13477 | Aug 05, 2026 |
IBM QRadar 7.5/7.6 Arbitrary Command Execution via Improper Input Validation (Vuln in 7.5.0 & 7.6.0IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input. |
|
| CVE-2026-8400 | Aug 05, 2026 |
IBM WebSphere AppServer 8.5/9.0 ORB flaw permits arbitrary class loading via IIOPIBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes. |
|
| CVE-2026-12730 | Aug 05, 2026 |
IBM Business Automation Workflow 24-26: Hostname Cert Mismatch (CVE-2026-12730)IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim Fix 009 IBM Business Automation Workflow fails to properly verify that the hostname matches the server certificate potentially allowing connections to an attacker-controlled server. |
|
| CVE-2026-12762 | Aug 05, 2026 |
IBM Cloud Pak FA 24.0.0-26.0.0 Info Disclosure via Manifest FilesIBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensitive information exposed in manifest files. |
|
| CVE-2026-10569 | Jul 30, 2026 |
IBM UrbanCode Deploy 7.x/8.x: Exposure of Sensitive Info in Plugin LogsIBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 is susceptible to an Exposure of Sensitive Information Vulnerability in plugin output logs. This exposure could allow an attacker with access to the logs to potentially obtain senstive values related to that step. |
|
| CVE-2026-11536 | Jul 30, 2026 |
IBM WAS 9.0/8.5 RCE via SOAP/JMX ConnectorIBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector. |
|
| CVE-2026-12946 | Jul 30, 2026 |
IBM Langflow RCE via User Input (v1.0.01.10.0)IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code. |
|
| CVE-2026-13444 | Jul 30, 2026 |
IBM Langflow OSS 1.0.0-1.10.1 Stale Vector Access via Chroma Persist DirIBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents by creating their own flow with matching Chroma persist_directory and collection_name values. The attacker receives exact victim content in their workflow output despite having no authorization to read the victim's flow. Additionally, the attacker can pollute the victim's collection by inserting their own documents into the shared namespace. |
|
| CVE-2024-25039 | Jul 30, 2026 |
IBM DOORS Web Access 9.7.2.1-9.7.2.11 Slowloris DoSIBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the web server to become unresponsive. |
|
| CVE-2024-40683 | Jul 30, 2026 |
IBM Ops Analytics Log Analysis 1.3-1.3.8: Session stays after pw changeIBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 does not invalidate session after a password chance which could allow an authenticated user to impersonate another user on the system. |
|
| CVE-2026-10545 | Jul 30, 2026 |
IBM Planning Analytics Local Open Redirect (2.1.0-2.1.21) via Crafted URLIBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect users to arbitrary external websites via a crafted URL. If used in SSO authentication flows, this could result in exposure of session tokens and allow attackers to hijack user sessions. |
|
| CVE-2026-12943 | Jul 30, 2026 |
IBM HMC RCE via Unauth Input v10.3.1050-1064 / v11.1.1110-1112IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input. |
|
| CVE-2026-12733 | Jul 30, 2026 |
IBM DataPower Gateway: Remote DoS via Resource ExhaustionIBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations. |
And others... |
| CVE-2025-36374 | Jul 30, 2026 |
IBM DataPower Gateway XXE Vulnerability Exposes Sensitive DataIBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources. |
And others... |
| CVE-2026-12118 | Jul 30, 2026 |
IBM webMethods Integration <10.15 Unauth remote exec via deserializationIBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data. |
|
| CVE-2025-0152 | Jul 30, 2026 |
IBM DOORS & DOORS Web Access 9.6.x9.7.2.x XSS, vuln in Web UIIBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. |
|
| CVE-2026-10535 | Jul 30, 2026 |
IBM Db2 11.5.x/12.1.x Buffer Overflow in setgid helper db2flaccIBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc. |
|
| CVE-2026-10695 | Jul 30, 2026 |
IBM Db2 12.1.x Federated Server DoS via Non-Fenced QueriesIBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non fenced federated queries. |
|
| CVE-2026-11904 | Jul 30, 2026 |
Info Disclosure via Detailed Error Messages in IBM Verify ID Access 10.0-11.0.2IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. |
And others... |
| CVE-2026-10700 | Jul 30, 2026 |
Broken Access Control IDOR in IBM Langflow OSS 1.0.0-1.8.4 File APIIBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API that allow unauthorized access to user files.The /api/v1/files/images/{flow_id}/{file_name} endpoint does not enforce authentication or authorization checks, allowing unauthenticated remote attackers to retrieve image files associated with any flow by specifying a valid flow_id and file_name.Additionally, the /api/v1/files/download/{flow_id}/{file_name} endpoint requires authentication but fails to properly validate ownership of the requested resource. As a result, an authenticated user can access files belonging to other users by supplying arbitrary identifiers, leading to an authorization bypass (IDOR).Successful exploitation may result in unauthorized disclosure of sensitive data, including files stored in private flows. This issue breaks tenant isolation in multi-user deployments. |
|
| CVE-2026-13435 | Jul 30, 2026 |
IBM Langflow OSS <1.10.2 Improper Input Validation in PythonREPL SandboxIBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation. |
|
| CVE-2026-12942 | Jul 30, 2026 |
IBM Langflow OSS 1.0.0-1.10.1 Dir Traversal via dotdot URLIBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary files on the system. |
|