CVE-2026-9186 PUBLISHED

Langflow is vulnerable to stored cross-site scripting and IP spoofing due to unsanitized Markdown rendering and untrusted proxy header trust

Assigner: ibm
Reserved: 21.05.2026 Published: 04.09.2026 Updated: 04.09.2026

IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 header, enabling arbitrary writes to IDE config files (~/.cursor/mcp.json, etc.).

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS Score: 6.5

Product Status

Vendor IBM
Product Langflow OSS
Versions
  • affected from 1.0.0 to 1.11.2 (incl.)

Solutions

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.11.3 https://pypi.org/project/langflow/

Credits

  • odgrso GMO CyberSecurity by Ierae inc, Edward-x (YLChen-007) finder

References

Problem Types

  • CWE-284 Improper Access Control CWE