VulnWatch VulnWatch
← Back to dashboard
High nvd · CVE-2026-17626

CVE-2026-17626: IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitiv

Published Aug 5, 2026 CVSS 8.8

IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Docker-based MCP servers due to incomplete filtering of dangerous Docker volume-mount and device-mapping arguments.

Affected AI Products

mcp server langflow
Get the weekly digest. Every Monday: top AI security stories of the week. Free.