CVE-2026-12763: IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context
Summary
IBM Langflow OSS versions 1.0.0 through 1.11.5 has a security flaw where a logged-in attacker can view another user's MCP (Model Context Protocol, a system for connecting AI tools to external services) server settings because the cache key isolation (the method that keeps different users' data separate in temporary storage) is not working properly in the MCP Tools component.
Vulnerability Details
4.2(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
network
high
low
none
September 14, 2026
Classification
Affected Vendors
Related Issues
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
CVE-2024-27444: langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-12763
First tracked: September 14, 2026 at 08:07 PM
Classified by LLM (prompt v3) · confidence: 85%