CVE-2026-6542Disclosure(langflow / langflow)

LOWCVSS 8.1 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

IBM Langflow OSS 1.0.0 through 1.8.4 could allow any user to supply a flow_id to read transaction logs and vertex build data belonging to other users, and to delete persisted vertex build data for another user's flow.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langflow

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
langflow

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-30: 3Technical Details · 2026-04-30: 204-30
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-6542 IBM Langflow OSS 1.0.0 through 1.8.4 could allow any user to supply a flow_id to read transaction logs and vertex build data belonging to other users, and to delete per… https://www.cve.org/CVERecord?id=CVE-2026-6542

    Post summary

    The post announces that CVE‑2026‑6542 in IBM Langflow OSS permits users to read and delete other users' logs by supplying a flow_id, but offers no PoC, exploit, or patch details.

    00020141
    57.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6542 Unauthorized Access and Data Deletion in IBM Langflow OSS ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6542 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet announces CVE-2026-6542, highlighting unauthorized access and data deletion issues in IBM Langflow OSS, and provides links to vulnerability details and scanning alerts.

    0000045
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-6542 IBM Langflow OSS 1.0.0 through 1.8.4 could allow any user to supply a flow_id to read transaction logs and vertex build data belonging to other users, and to delete per… https://www.cve.org/CVERecord?id=CVE-2026-6542 ----- Traducción: CVE-2026-6542 IBM… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑6542 in IBM Langflow OSS, describing a data‑disclosure and deletion flaw, with no mention of PoC, exploit code, or active exploitation.

    0000023
    75 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applangflowlangflow---

Explore more