Executive brief
IBM Langflow OSS, a visual tool for building AI workflows, contains a security flaw in how it handles data storage for different users. An attacker with basic user access can access or modify private AI data belonging to other users by reusing their storage namespaces. This could lead to the exposure of sensitive information or the manipulation of AI query results, potentially impacting the reliability of business operations.
Technical details
A vulnerability in IBM Langflow OSS versions 1.0.0 through 1.10.1 stems from absent user scoping in persistent FAISS vector store namespaces. An authenticated attacker can exploit this lack of path ownership enforcement to access or modify vector documents belonging to other users. This results in cross-user information disclosure and persistent poisoning of query results (integrity impact). The issue is resolved in version 1.10.2.
Affected products
- IBM Langflow OSS 1.0.0 through 1.10.1
Timeline
- 2026-07-14: disclosed: Initial publication of the security bulletin by IBM
- 2026-07-28: advisory: NVD publication date
- 2026-07-14: patched: Remediation version 1.10.2 recommended in bulletin