CVE-2026-6542

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
30/04/2026
Last modified:
04/05/2026

Description

IBM Langflow OSS 1.0.0 through 1.8.4 could allow any user to supply a flow_id to read transaction logs and vertex build data belonging to other users, and to delete persisted vertex build data for another user's flow.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* 1.0.0 (including) 1.9.0 (excluding)


References to Advisories, Solutions, and Tools