{"data":{"id":"65a40f95-0857-4e83-94c1-5678d4f8146d","title":"CVE-2026-18904: IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject unauthori","summary":"IBM Langflow OSS (open-source software) versions 1.0.0 through 1.11.1 has a security flaw where a namespace collision (a situation where two different things accidentally share the same name or identifier) between user identifiers allows attackers to steal sensitive information and insert unauthorized messages into the system.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-18904","publishedAt":"2026-08-28T22:16:47.227Z","cveId":"CVE-2026-18904","cweIds":["CWE-639"],"cvssScore":"8.2","cvssSeverity":"high","severity":"high","attackType":["data_extraction"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["IBM Langflow"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-28T22:16:47.227Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}