CVE-2026-7664

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
22/06/2026
Last modified:
26/06/2026

Description

IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* 1.0.0 (including) 1.8.4 (including)


References to Advisories, Solutions, and Tools