CVE-2026-7663
critical · 9.1IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.
9.1
CVSS
0.5%
EPSS (exploit prob.)
43rd
EPSS percentile
2026-06-30
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-285CWE-863
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| langflow | langflow | >= 1.0.0, < 1.10.0 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2026-7663