Vulnerability Description
IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of other users via session_id collision. The MemoryComponent.retrieve_messages and store_message methods filter on session_id without validating flow_id or user_id ownership, enabling cross-user information disclosure through multiple authenticated API endpoints including /api/v1/run/*, /api/v1/responses, and /api/v2/workflow/*. This vulnerability only affects multi-user deployments with LANGFLOW_AUTO_LOGIN=False.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Langflow | Langflow | >= 1.0.0, < 1.11.0 |
Related Weaknesses (CWE)
References
- https://www.ibm.com/support/pages/node/7282647Vendor Advisory
FAQ
What is CVE-2026-9130?
CVE-2026-9130 is a vulnerability with a CVSS score of 7.1 (HIGH). IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of other users via session_id collisio...
How severe is CVE-2026-9130?
CVE-2026-9130 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-9130?
Check the references section above for vendor advisories and patch information. Affected products include: Langflow Langflow.