{"data":{"id":"60999fa6-fc1d-4ee7-bb6b-014f4662c0a0","title":"CVE-2026-9103: IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authenti","summary":"IBM Langflow OSS versions 1.0.0 through 1.10.0 have a critical vulnerability in the /api/v1/login/auto_login endpoint that allows unauthenticated attackers to gain full administrative access by obtaining long-lived superuser bearer tokens (special credentials that prove you have admin privileges) when AUTO_LOGIN is enabled by default. The vulnerability is made worse by overly permissive CORS settings (rules controlling which websites can access the application), which can expose these tokens to unintended websites.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-9103","publishedAt":"2026-07-17T19:17:19.277Z","cveId":"CVE-2026-9103","cweIds":["CWE-306"],"cvssScore":"9.8","cvssSeverity":"critical","severity":"critical","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["IBM Langflow"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-07-17T19:17:19.277Z","capecIds":["CAPEC-115"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":["AML.T0010"]}}