{"data":{"id":"6c0ac678-9b31-4275-baa7-70003bdcfad9","title":"CVE-2026-13442: IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only","summary":"IBM Langflow OSS (open-source software) versions 1.0.0 through 1.10.1 has a vulnerability where attackers can reuse another user's FAISS namespace (a storage space for vector embeddings, which are numerical representations of data) to access private vector content and manipulate search results. This allows attackers to see information they shouldn't have access to and corrupt the results returned to other users.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-13442","publishedAt":"2026-07-28T21:17:25.387Z","cveId":"CVE-2026-13442","cweIds":["CWE-520"],"cvssScore":"7.1","cvssSeverity":"high","severity":"high","attackType":["data_extraction","rag_poisoning"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["IBM Langflow","FAISS"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-07-28T21:17:25.387Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"rag","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":["AML.T0020","AML.T0051.001"]}}