VulnWatch VulnWatch
← Back to dashboard
Critical nvd · CVE-2026-7664

CVE-2026-7664: IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and

Published Jun 22, 2026 CVSS 9.8

IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.

Affected AI Products

langflow
Get the weekly digest. Every Monday: top AI security stories of the week. Free.