CVE-2026-13444CWE-520

CVE-2026-13444

High · published July 30, 2026

CVSS v3.1
8.1
EPSS
0%
Percentile
11.5
In the wild
Unconfirmed
What it is

IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents by creating their own flow with matching Chroma persist_directory and collection_name values. The attacker receives exact victim content in their workflow output despite having no authorization to read the victim's flow. Additionally, the attacker can pollute the victim's collection by inserting their own documents into the shared namespace.

The record
Technical detail
CVSS v3.1
8.1 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00212 · 11.5th percentile
Weakness
CWE-520 · .NET Misconfiguration: Use of Impersonation
Published
2026-07-30T23:17Z
Affected products (1)
ProductVersionsFixed in
langflow/langflow≥ 1.0.0, < 1.10.21.10.2
References (1)
EPSS history
Timeline
  • 30 JUL 18:38Z
    Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
    cvelistv5