Executive brief
IBM Langflow OSS is an open-source platform for building and managing AI language workflows. A missing authentication check on the user registration endpoint allows attackers to overwrite the administrator's email address and gain unauthorized control of the server, potentially using it to send phishing emails or spam.
Technical details
The vulnerability is an authentication bypass in the registration endpoint of IBM Langflow OSS versions 1.0.0 through 1.10.0. The registration function fails to validate that the user attempting to modify administrator credentials is actually authorized, allowing unauthenticated remote attackers to overwrite the admin email address. This enables account takeover and abuse of the server as an outbound mail relay. The attack requires only network access to the registration endpoint and no user interaction. A patch or update to a patched version is recommended.
Affected products
- IBM Langflow OSS 1.0.0 through 1.10.0
Timeline
- 2026-08-19: disclosed