Executive brief
IBM Langflow OSS, a tool used to build and manage AI workflows, contains a security flaw that allows unauthorized individuals to access private project data. Attackers can bypass security controls to view confidential files, flow definitions, and metadata belonging to other users. In some cases, an attacker could even execute AI tools with administrative privileges, potentially leading to a full compromise of the application's data and operations.
Technical details
An improper authorization vulnerability (CWE-285) exists in the Streamable MCP transport endpoint (/api/v1/mcp/project/{project_id}/streamable) of IBM Langflow OSS. The flaw allows unauthenticated remote attackers to bypass project ownership checks and execute Model Context Protocol (MCP) operations against OAuth-authenticated projects. Attackers can enumerate private tool metadata, read confidential flow definitions and project files, and execute MCP tools with superuser privileges. This issue specifically affects the Streamable transport path when MCP Composer is enabled and does not impact the SSE endpoint. A fix is available in version 1.10.0.
Affected products
- IBM Langflow OSS 1.0.0 - 1.9.6
Timeline
- 2026-06-23: advisory: Initial publication by IBM
- 2026-06-30: disclosed: NVD publication date
- 2026-06-30: patched: Remediation available in version 1.10.0