---
id: CVE-2026-85025
title: >-
  IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated
  attacker to execute arbitrary code and access or modify chat sessions through
  publicly shared MCP project endpoints due to improper enforcement of
  public-flow …
summary: >-
  IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated
  attacker to execute arbitrary code and access or modify chat sessions through
  publicly shared MCP project endpoints due to improper enforcement of
  public-flow …
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-863
vendor: langflow
product: langflow
affected:
  - 'langflow >= 1.0.0, < 1.11.6'
patched:
  - langflow 1.11.6
published: '2026-09-10'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T17:19:17.853'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85025'
references:
  - url: 'https://www.ibm.com/support/pages/node/7286666'
    label: psirt@us.ibm.com
tags:
  - nvd
  - cve.org
epss: 0.00614
epssPercentile: 0.47189
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-11T00:00:00+00:00'
ingestedAt: '2026-09-14T15:23:07.483Z'
---

## Overview

IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow security restrictions and session isolation controls.

## Affected

- `langflow >= 1.0.0, < 1.11.6`

## Remediation

Upgrade past the affected range:

- `langflow 1.11.6`
