High
nvd
·
CVE-2026-8056
CVE-2026-8056: IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API
Published Jul 17, 2026
CVSS 8.8
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API. A critical security flaw exists in the parameter filtering mechanism within the apply_tweaks() function.
Affected AI Products
langflow