CVE-2026-9186: IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration i
Summary
IBM Langflow OSS versions 1.0.0 through 1.11.2 have a security weakness where attackers who are logged in can trick the system into thinking they are accessing from localhost (the local computer) by faking an X-Forwarded-For header (a piece of information that says where a request came from). This allows them to bypass security restrictions and modify important configuration files that control IDE (integrated development environment, the tool programmers use to write code) settings.
Vulnerability Details
6.5(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
network
low
low
none
September 4, 2026
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-9186
First tracked: September 4, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 92%