IBM Langflow OSS 1.0.0 through 1.8.4 could allow any user to supply a flow_id to read transaction logs and vertex build data belonging to other users, and to delete persisted vertex build data for another user's flow.
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/7270886 | Third Party Advisory |
Configurations
History
04 May 2026, 18:21
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* | |
| First Time |
Langflow langflow
Langflow |
|
| References | () https://www.ibm.com/support/pages/node/7270886 - Third Party Advisory |
30 Apr 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-30 22:16
Updated : 2026-05-04 18:21
NVD link : CVE-2026-6542
Mitre link : CVE-2026-6542
CVE.ORG link : CVE-2026-6542
JSON object : View
Products Affected
langflow
- langflow
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
