CVE-2026-12763: IBM Langflow OSS
Medium severity, CVSS 4.2. EPSS: 0.1% chance of exploitation in the next 30 days.
IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context due to improper cache key isolation in the MCP Tools component.
Affected products
- IBM Langflow OSS: from 1.0.0, up to and including 1.11.5
Published 2026-09-14. Last modified 2026-09-16.