Vulnerability Description
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication tokens for any user.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Langflow | Langflow | >= 1.0.0, < 1.10.1 |
| Apple | Macos | - |
| Linux | Linux Kernel | - |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://www.ibm.com/support/pages/node/7278934Vendor Advisory
FAQ
What is CVE-2026-7872?
CVE-2026-7872 is a vulnerability with a CVSS score of 7.5 (HIGH). IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication tokens for any user.
How severe is CVE-2026-7872?
CVE-2026-7872 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-7872?
Check the references section above for vendor advisories and patch information. Affected products include: Langflow Langflow, Apple Macos, Linux Linux Kernel, Microsoft Windows.