Executive brief
IBM Langflow OSS, a tool used to build AI-powered applications, contains a flaw in its voice interaction feature that fails to keep different users' data separate. This allows a user to trick the system into using another person's paid API accounts (such as OpenAI or ElevenLabs) to process their own requests. This can lead to significant financial impact through billing fraud, where one customer unknowingly pays for another's usage, and potential exposure of audio history.
Technical details
The vulnerability exists in the voice mode subsystem (voice_mode.py) due to improper shared-state handling. Specifically, the ElevenLabsClientManager uses a process-global singleton that caches the first user's API key and reuses it for subsequent tenants without re-validating the user ID. Additionally, the OpenAI TTS client uses a cache keyed only by a client-controlled session ID, allowing an attacker to pre-position their own API key to intercept victim traffic. An authenticated attacker can exploit these flaws to cause requests from other users to be processed using incorrect upstream API credentials, resulting in cross-tenant billing fraud and TOS-accountability redirection. The issue is fixed in version 1.10.1.
Affected products
- IBM Langflow OSS 1.0.0 - 1.10.0
Timeline
- 2026-06-26: advisory: Initial publication by IBM
- 2026-06-30: disclosed: NVD publication date