VulnWatch VulnWatch
← Back to dashboard
High nvd · CVE-2026-7872

CVE-2026-7872: IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing

Published Jul 17, 2026 CVSS 7.5

IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication tokens for any user.

Affected AI Products

langflow
Get the weekly digest. Every Monday: top AI security stories of the week. Free.