Executive brief
IBM Langflow is an open-source workflow automation platform that allows users to build and execute AI-powered flows. CVE-2026-18904 enables an unauthenticated attacker to read and modify another user's chat history and injected messages by exploiting a flaw where user IDs can be reused as session identifiers. This could expose confidential conversation data and allow attackers to impersonate legitimate users within the platform.
Technical details
The vulnerability exists in Langflow's flow metadata endpoint, which exposes the owner user_id without proper namespace isolation. An attacker can reuse the exposed user_id as a client_id to create a session namespace collision with the legitimate owner, bypassing the namespace containment mechanism. The flaw is a CWE-639 authorization bypass in the public-playground chat history feature, requiring no authentication and no user interaction. An unauthenticated attacker can read chat messages and inject unauthorized messages into another user's session. The vulnerability affects Langflow OSS versions 1.0.0 through 1.11.1 and is patched in version 1.11.2.
Affected products
- IBM Langflow 1.0.0-1.11.1
Timeline
- 2026-08-28: disclosed: IBM published CVE-2026-18904 security bulletin
- 2026-08-21: patched: IBM recommends upgrading to Langflow OSS 1.11.2