← Back

CVE-2026-7872

nvd nist
Published: Jul 17, 2026Modified: Jul 20, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Exploitability: 2.8 / Impact: 5.2
Source: NVD

Description

IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication tokens for any user.

Affected (1)

Products: Langflow: Langflow
1 product
Langflow
Configuration A
1 vulnerable · 3 platform
Vulnerable SoftwareAffected Versions
From 1.0.0 to 1.10.1
Running on/withPlatform Versions
Apple
Macos
All versions
Linux
Linux Kernel
All versions
Microsoft
Windows
All versions

References (1)

Source: psirt@us.ibm.com
Vendor Advisory

Timeline

No history available yet.