VulnWatch VulnWatch
← Back to dashboard
Medium nvd · CVE-2026-12763

CVE-2026-12763: IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context

Published Sep 14, 2026 CVSS 4.2

IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context due to improper cache key isolation in the MCP Tools component.

Affected AI Products

mcp server langflow
Get the weekly digest. Every Monday: top AI security stories of the week. Free.