Junglewise Threat Intelligence

CVE-2026-17626: IBM Langflow OSS arbitrary file access via Docker MCP servers

CVE-2026-17626 · Severity: high · CVSS 8.8 · Published 2026-08-05

Technologies: IBM Langflow OSS, Langflow. Vendors: IBM, Langflow.

Executive brief

IBM Langflow is an open-source platform for building and managing language model applications. An authenticated attacker can read, modify, or delete sensitive files on the host system by exploiting incomplete validation of Docker volume-mount and device-mapping parameters in MCP (Model Context Protocol) server configurations. This could expose database files, JWT secrets, and other critical system data, leading to complete compromise of the Langflow deployment and potentially the underlying infrastructure.

Technical details

The vulnerability exists in Langflow's Docker-based MCP server implementation, which fails to properly filter dangerous Docker volume-mount (--volume/-v) and device-mapping (--device) arguments. An authenticated user can craft malicious MCP server configurations with unfiltered mount or device parameters to access arbitrary host filesystem locations. The attack requires authentication (PR:L) and network access, but bypasses host isolation controls. An attacker can achieve full confidentiality, integrity, and availability impact by reading sensitive files (database, secrets, other users' documents), modifying configuration files, or executing arbitrary commands through mounted privileged devices. IBM recommends upgrading to Langflow OSS 1.11.0 or later; no workarounds are available.

Affected products

  • IBM Langflow OSS 1.0.0 through 1.10.3

Timeline

  • 2026-07-31: disclosed
  • 2026-08-05: advisory

References

Related threats