Back to CVE List

CVE-2026-10140

CRITICAL SEVERITY

CVSS Score & Metrics

Base Score
9.6 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Vulnerability Description

IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. An authenticated attacker can manipulate cache state to cause requests from other users to be processed using incorrect upstream API credentials, leading to cross-tenant billing and accountability misattribution.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-639
Source
NVD
Vendor
IBM
Product
Langflow OSS

External References

Discussion (0)

Add Comment

No comments yet. Be the first!