CVE-2026-7663
CRITICAL9.1CVSS v3
—CVSS v2
0.26%
EPSS (exploit probability)
CWE-285CWE
Description
IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.
CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected routers (0)
No routers currently mapped to this CVE in our database.