{"data":{"id":"a1d56b18-67c5-4b58-ba15-4e35130fb9e6","title":"CVE-2026-17627: IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information and in","summary":"IBM Langflow OSS (an open-source tool for building AI workflows) versions 1.0.0 through 1.10.2 has a security flaw where authenticated attackers (users with login credentials) can access sensitive information and add fake messages to workflow history because the system doesn't properly check what users are allowed to do.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-17627","publishedAt":"2026-09-04T17:16:55.380Z","cveId":"CVE-2026-17627","cweIds":["CWE-639"],"cvssScore":"4.9","cvssSeverity":"medium","severity":"medium","attackType":["data_extraction"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["IBM Langflow"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N","attackVector":"network","attackComplexity":"high","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-04T17:16:55.380Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}