VulnWatch VulnWatch
← Back to dashboard
High nvd · CVE-2026-8056

CVE-2026-8056: IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API

Published Jul 17, 2026 CVSS 8.8

IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API. A critical security flaw exists in the parameter filtering mechanism within the apply_tweaks() function.

Affected AI Products

langflow
Get the weekly digest. Every Monday: top AI security stories of the week. Free.