Unrated severityNVD Advisory· Published Jul 30, 2026· Updated Jul 30, 2026
Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
CVE-2026-13444
Description
IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents by creating their own flow with matching Chroma persist_directory and collection_name values. The attacker receives exact victim content in their workflow output despite having no authorization to read the victim's flow. Additionally, the attacker can pollute the victim's collection by inserting their own documents into the shared namespace.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: 1.0.0 - 1.10.1
- Range: 1.0.0 - 1.10.1
Patches
Vulnerability mechanics
References
1- www.ibm.com/support/pages/node/7279989mitrevendor-advisorypatch
News mentions
0No linked articles in our index yet.