High severity7.5NVD Advisory· Published Jul 17, 2026· Updated Jul 20, 2026
CVE-2026-7872
CVE-2026-7872
Description
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication tokens for any user.
Affected products
3cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*range: >=1.0.0,<1.10.1
- (no CPE)range: >=1.0.0,<1.10.0
- Range: 1.0.0 - 1.10.0
Patches
Vulnerability mechanics
References
1- www.ibm.com/support/pages/node/7278934nvdVendor Advisory
News mentions
0No linked articles in our index yet.