• PATCH AVAILABLE

CVE-2026-85025: pre-auth remote code execution in IBM Langflow OSS

An unauthenticated attacker can execute arbitrary code and read or modify chat sessions on IBM Langflow OSS by targeting publicly shared MCP project endpoints, tracked as CVE-2026-85025. The issue affects Langflow OSS versions 1.0.0 through 1.11.5 and stems from insufficient enforcement of public-flow and session isolation controls; an attacker only needs network access to a publicly exposed MCP project endpoint to exploit the flaw.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00614
CWE
CWE-863
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Treat this as high priority: an attacker needs no account to reach exposed MCP endpoints, so immediately remove or restrict any publicly shared project endpoints and follow IBM’s remediation guidance.

What is CVE-2026-85025?

An unauthenticated attacker can execute arbitrary code and read or modify chat sessions on IBM Langflow OSS by targeting publicly shared MCP project endpoints, tracked as CVE-2026-85025. The issue affects Langflow OSS versions 1.0.0 through 1.11.5 and stems from insufficient enforcement of public-flow and session isolation controls; an attacker only needs network access to a publicly exposed MCP project endpoint to exploit the flaw.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of IBM Langflow OSS are affected?

BRANCHAFFECTEDFIXED
1.x1.0.0 – 1.11.5

Is CVE-2026-85025 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-85025

  1. Disable or unpublish any publicly shared MCP project endpoints until a fix is applied.
  2. Apply IBM’s guidance or updates for Langflow OSS as soon as they are available.
  3. Restrict network access to MCP endpoints (VPN, allowlists) and monitor access logs for anomalous requests.
  4. Prepare to install vendor patches and verify session isolation after updating.

Frequently asked questions

Is CVE-2026-85025 being actively exploited?

There are no public reports of exploitation of CVE-2026-85025 as of 2026-09-29.

Which Langflow OSS versions are affected by CVE-2026-85025?

Langflow OSS versions 1.0.0 through 1.11.5 are listed as affected by CVE-2026-85025.

Is there a patch for CVE-2026-85025?

A remediation is available from IBM; follow the vendor’s published guidance or updates for Langflow OSS to obtain and apply the fix.

Does CVE-2026-85025 require authentication?

No, the vulnerability can be exploited by an unauthenticated attacker if a Langflow OSS MCP project endpoint is publicly accessible.

References