IBM Langflow OSS <=1.11.2 Localhost Bypass via X-Forwarded-For Spoof
CVE-2026-9186 Published on September 4, 2026

Langflow is vulnerable to stored cross-site scripting and IP spoofing due to unsanitized Markdown rendering and untrusted proxy header trust
IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 header, enabling arbitrary writes to IDE config files (~/.cursor/mcp.json, etc.).

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-9186 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity, and no impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
NONE
Integrity Impact:
HIGH
Availability Impact:
NONE

Weakness Type

What is an Authorization Vulnerability?

The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVE-2026-9186 has been classified to as an Authorization vulnerability or weakness.


Products Associated with CVE-2026-9186

Want to know whenever a new CVE is published for IBM Langflow Oss? stack.watch will email you.

 

Affected Versions

IBM Langflow OSS: