Loading market data...
← Back to CVE feed

CVE-2026-12763

MEDIUM CVSS 4.2 View on NVD ↗

Description

IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context due to improper cache key isolation in the MCP Tools component.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Published: Sep 14, 2026 21:17 UTC Modified: Sep 14, 2026 21:17 UTC