CVE-2026-85025EPSS p47.6%
CVE-2026-85025CVE-2026-85025
langflow / langflow
Description
IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow security restrictions and session isolation controls.
Scoring
| CVSS | 9.8 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.61% probability of exploitation · percentile 47.6% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-15 |