{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-85025","assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","state":"PUBLISHED","assignerShortName":"ibm","dateReserved":"2026-09-02T19:57:50.612Z","datePublished":"2026-09-10T20:58:37.175Z","dateUpdated":"2026-09-11T13:46:25.166Z"},"containers":{"cna":{"providerMetadata":{"orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm","dateUpdated":"2026-09-10T20:58:37.175Z"},"title":"Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-863","description":"CWE-863 Incorrect Authorization","type":"CWE"}]}],"affected":[{"vendor":"IBM","product":"Langflow OSS","versions":[{"status":"affected","version":"1.0.0","lessThanOrEqual":"1.11.5","versionType":"semver"}],"cpes":["cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:langflow_oss:1.11.5:*:*:*:*:*:*:*"]}],"descriptions":[{"lang":"en","value":"IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow security restrictions and session isolation controls.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow security restrictions and session isolation controls.</p>"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286666","tags":["vendor-advisory","patch"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseSeverity":"CRITICAL","baseScore":9.8,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}}],"solutions":[{"lang":"en","value":"IBM strongly recommends addressing the vulnerability now by upgrading  Langflow OSS to version 1.11.6 https://pypi.org/project/langflow/","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>IBM strongly recommends addressing the vulnerability now by upgrading <a href=\"https://pypi.org/project/langflow/\" rel=\"nofollow\">Langflow OSS to version 1.11.6</a></p>"}]}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2026-85025","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"total"}],"version":"2.0.3","timestamp":"2026-09-11T13:11:55.927558Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-11T13:46:25.166Z"}}]}}