VulnWatch VulnWatch
← Back to dashboard
Critical nvd · CVE-2026-7663

CVE-2026-7663: IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and

Published Jun 30, 2026 CVSS 9.1

IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.

Affected AI Products

langflow
Get the weekly digest. Every Monday: top AI security stories of the week. Free.