What is CVE-2026-13442?
This CVE affects IBM Langflow OSS versions 1.0.0 through 1.10.1, where an attacker can reuse another user's FAISS namespace to access private vector content and poison query results, leading to cross-user information disclosure and limited integrity impact. Immediate update to the latest version is recommended.
Azərbaycanca: Bu CVE, IBM Langflow OSS-in 1.0.0-dən 1.10.1-ə qədər versiyalarında aşkarlanıb. Təcavüzkar başqa istifadəçinin FAISS namespace-ni təkrar istifadə edərək məxfi vektor məzmununu oxuya və sorğu nəticələrinə müdaxilə ilə çarpaz-istifadəçi məlumat ifşasına səbəb ola bilər. Dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284; shared vendor: IBM
FAQ2
Which versions of IBM Langflow OSS are vulnerable to CVE-2026-13442?
CVE-2026-13442 affects IBM Langflow OSS versions 1.0.0 through 1.10.1.
What can an attacker achieve by exploiting CVE-2026-13442?
An attacker can reuse another user's FAISS namespace to access private vector content and poison query results, leading to cross-user information disclosure and limited integrity impact.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.