CVE-2026-13442CWE-520

CVE-2026-13442

High · published July 29, 2026

CVSS v3.1
7.1
EPSS
0%
Percentile
7.0
In the wild
Unconfirmed
What it is

IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only vector content and influence later query results. This causes cross-user information disclosure and limited integrity impact through persistent poisoning of returned results.

The record
Technical detail
CVSS v3.1
7.1 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00174 · 7.0th percentile
Weakness
CWE-520 · .NET Misconfiguration: Use of Impersonation
Published
2026-07-29T01:17Z
Affected products (1)
ProductVersionsFixed in
langflow/langflow≥ 1.0.0, < 1.10.21.10.2
References (1)
EPSS history
Timeline
  • 28 JUL 20:55Z
    Langflow is affected by NET Misconfiguration: Use of Impersonation due to multiple unauthenticated and insufficiently authorized API endpoints
    cvelistv5