What is CVE-2026-13444?
CVE-2026-13444 is a vulnerability in IBM Langflow OSS versions 1.0.0 through 1.10.1 that allows an attacker to access another user's private vector documents. By creating their own flow with matching Chroma persist_directory and collection_name values, the attacker can receive exact victim content in their workflow output without authorization. Affected users should update to a patched version or restrict shared directory configurations.
Azərbaycanca: CVE-2026-13444, IBM Langflow OSS-nin 1.0.0-dən 1.10.1-ə qədər olan versiyalarında aşkarlanmış bir boşluqdur. Bu, təcavüzkara eyni Chroma persist_directory və collection_name dəyərlərindən istifadə edərək öz flow-unu yaratmaqla, digər istifadəçilərin şəxsi vektor sənədlərinə icazəsiz giriş imkanı verir. Təsirə məruz qalan istifadəçilər dərhal versiyalarını yeniləməli və ya müvəqqəti olaraq paylaşılan kataloq konfiqurasiyalarını məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: IBM
FAQ2
Which IBM product is affected by CVE-2026-13444?
IBM Langflow OSS versions 1.0.0 through 1.10.1 are affected by this vulnerability.
How can an attacker gain unauthorized access to another user's documents via CVE-2026-13444?
By creating their own flow with matching Chroma persist_directory and collection_name values, the attacker can receive exact victim content in their workflow output.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.