What is CVE-2026-10547?
IBM Langflow OSS versions 1.0.0 through 1.10.3 fail to properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/vertices endpoint, allowing an authenticated user to inject arbitrary graph data into a shared cache for any flow. This can lead to cross-user cache pollution and unauthorized workflow manipulation. Users should upgrade to the latest patched version immediately.
Azərbaycanca: IBM Langflow OSS 1.0.0-dən 1.10.3-ə qədər versiyalarda köhnəlmiş POST /api/v1/build/{flow_id}/vertices endpoint-də mülkiyyət yoxlanışı düzgün aparılmır, bu da autentifikasiya olunmuş istifadəçiyə başqa istifadəçinin flow-u üçün ortaq cache-ə ixtiyari graph məlumatı daxil etməyə imkan verir. Bu zəiflik cross-user cache pollution və icazəsiz iş axınına səbəb ola bilər. İstifadəçilərə dərhal ən son versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: IBM
FAQ2
Which versions of IBM Langflow OSS are affected by CVE-2026-10547?
Versions 1.0.0 through 1.10.3.
What action can an authenticated user perform by exploiting CVE-2026-10547?
Inject arbitrary graph data into a shared cache for another user's flow, leading to cross-user cache pollution and unauthorized workflow manipulation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.