CVE-2026-7663Disclosure(langflow / langflow)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch langflow langflow systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-285CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langflow

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-07-09); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
langflow

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-09: 1Mentions · 2026-07-26: 1Patch / Workaround · 2026-07-26: 1Technical Details · 2026-07-09: 1Technical Details · 2026-07-26: 107-0907-26
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-091
Disclosure1
2026-07-261
Patch1
Full discourse2 posts
  • takenaka hiroya@Joe_Biden_ja
    Patch

    「脆弱性対応ウォッチ」にCVE-2026-7663の新しい記事を追加しました。IBM Langflow OSS 1.0.0〜1.9.6にCVSS 9.8の深刻な脆弱性があり、未認証の越境アクセスが可能です。バージョン1.9.7で修正済みですので、早めの対応をおすすめします。 https://cve.autoarticles.net/cve/CVE-2026-7663

    Post summary

    CVE‑2026‑7663 is a severe (CVSS 9.8) unauthenticated access flaw in IBM Langflow OSS versions 1.0.0‑1.9.6, fixed in 1.9.7, and users are urged to update promptly.

    0000084
    562 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    Langflowに重大な脆弱性6件、IBMが発見-未認証RCEからAPIキーの越境流用まで広範囲に影響(CVE-2026-10134、CVE-2026-7803、CVE-2026-7871、CVE-2026-7873、CVE-2026-10140、CVE-2026-7663) https://rocket-boys.co.jp/security-measures-lab/langflow-unauthenticated-rce-cve-2026-10134/ #セキュリティ対策Lab #security #securitynews

    Post summary

    IBM has identified six critical Langflow vulnerabilities, ranging from unauthenticated RCE to API key hijacking, but no PoC, exploit, or patch is referenced.

    00000158
    462 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applangflowlangflow---

Explore more