IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/7277570 | Vendor Advisory |
Configurations
History
02 Jul 2026, 18:19
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-863 | |
| References | () https://www.ibm.com/support/pages/node/7277570 - Vendor Advisory | |
| First Time |
Langflow langflow
Langflow |
|
| CPE | cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* |
30 Jun 2026, 20:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-30 20:17
Updated : 2026-07-02 18:19
NVD link : CVE-2026-7663
Mitre link : CVE-2026-7663
CVE.ORG link : CVE-2026-7663
JSON object : View
Products Affected
langflow
- langflow
