What is CVE-2026-17626?
CVE-2026-17626 is a vulnerability in IBM Langflow OSS versions 1.0.0 through 1.10.3, allowing an authenticated attacker to read, modify, or expose sensitive host files via Docker-based MCP servers due to incomplete filtering of dangerous Docker volume-mount and device-mapping arguments.
Azərbaycanca: CVE-2026-17626, IBM Langflow OSS-in 1.0.0-dən 1.10.3-ə qədər olan versiyalarına təsir edən, autentifikasiya olunmuş hücumçunun Docker əsaslı MCP serverləri vasitəsilə təhlükəli Docker volume-mount və device-mapping arqumentlərinin tam süzgəcdən keçirilməməsi səbəbindən host sistemdəki həssas faylları oxumasına, dəyişdirməsinə və ya ifşa etməsinə imkan verən zəiflikdir.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: IBM
FAQ2
Which product is affected by CVE-2026-17626?
CVE-2026-17626 affects IBM Langflow OSS versions 1.0.0 through 1.10.3.
Does exploiting this vulnerability require authentication?
Yes, exploiting CVE-2026-17626 requires the attacker to be authenticated.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.