Executive brief
IBM Langflow OSS, a tool used to build AI-powered workflows, contains a security flaw that allows users to interfere with each other's work. An authenticated user could view the activity logs of other users' build jobs or cancel those jobs while they are running. This could lead to the exposure of sensitive development activity or cause operational disruptions by stopping active AI model builds.
Technical details
The vulnerability is classified as an Authorization Bypass Through User-Controlled Key (CWE-639). It stems from improper access control within the log retrieval mechanism and the presence of unauthenticated build endpoints. A network-based attacker with low-privileged authenticated access can exploit these flaws to disclose build activity logs belonging to other users or manipulate in-flight build jobs (such as canceling them). The issue is resolved in Langflow OSS version 1.10.2.
Affected products
- IBM Langflow OSS 1.0.0 through 1.10.1
Timeline
- 2026-07-14: advisory: Initial publication by IBM
- 2026-07-30: disclosed: NVD publication date
- 2026-07-14: patched: Remediation available in version 1.10.2