Medium
nvd
·
CVE-2026-12763
CVE-2026-12763: IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context
Published Sep 14, 2026
CVSS 4.2
IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context due to improper cache key isolation in the MCP Tools component.
Affected AI Products
mcp server
langflow