← voltar
CVE-2026-10560highCWE-287

Unauthenticated Access to Private Flow Build Events and Cancellation in Langflow OSS

21Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 8.2epss 0.5%
probabilidade de exploração
0.5%top 59% das CVEs
exploração observada
nãonenhuma fonte reporta
IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoints that allows an unauthenticated attacker to read build event data or cancel jobs using a valid job identifier, resulting in information disclosure and denial of service.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Produtos afetados
IBM · Langflow OSS