{"data":{"id":"a68518f7-81e9-41d9-aa65-d40309628e3f","title":"CVE-2026-12763: IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context ","summary":"IBM Langflow OSS versions 1.0.0 through 1.11.5 has a security flaw where a logged-in attacker can view another user's MCP (Model Context Protocol, a system for connecting AI tools to external services) server settings because the cache key isolation (the method that keeps different users' data separate in temporary storage) is not working properly in the MCP Tools component.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-12763","publishedAt":"2026-09-14T21:17:00.440Z","cveId":"CVE-2026-12763","cweIds":["CWE-306"],"cvssScore":"4.2","cvssSeverity":"medium","severity":"medium","attackType":["data_extraction"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["IBM Langflow"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","attackVector":"network","attackComplexity":"high","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-14T21:17:00.440Z","capecIds":["CAPEC-115"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}