Medium severity6.5NVD Advisory· Published Apr 30, 2026· Updated May 4, 2026
CVE-2026-6542
CVE-2026-6542
Description
IBM Langflow OSS 1.0.0 through 1.8.4 could allow any user to supply a flow_id to read transaction logs and vertex build data belonging to other users, and to delete persisted vertex build data for another user's flow.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.ibm.com/support/pages/node/7270886nvdThird Party Advisory
News mentions
4- ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ StoriesThe Hacker News · May 14, 2026
- ⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and MoreThe Hacker News · May 11, 2026
- Metasploit Wrap-Up 04/25/2026Rapid7 Blog · Apr 24, 2026
- 23rd March – Threat Intelligence ReportCheck Point Research · Mar 23, 2026