CVE-2026-13442: IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only
Summary
IBM Langflow OSS (open-source software) versions 1.0.0 through 1.10.1 has a vulnerability where attackers can reuse another user's FAISS namespace (a storage space for vector embeddings, which are numerical representations of data) to access private vector content and manipulate search results. This allows attackers to see information they shouldn't have access to and corrupt the results returned to other users.
Vulnerability Details
7.1(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
network
low
low
none
July 28, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
CVE-2024-27444: langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-13442
First tracked: July 28, 2026 at 08:04 PM
Classified by LLM (prompt v3) · confidence: 85%