CVE-2026-7664: Langflow
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.
Affected products
- Langflow Langflow: from 1.0.0, up to and including 1.8.4
Published 2026-06-22. Last modified 2026-06-26.