What is CVE-2026-7646?
CVE-2026-7646: IBM Langflow OSS versions 1.0.0 through 1.10.3 contain a vulnerability that allows arbitrary file read from the server filesystem. An attacker can access sensitive data, including other users' uploaded documents, the JWT signing secret, the SQLite database, and process environment variables, by sending a crafted MCP `resources/read` request with a URL-encoded path.
Azərbaycanca: CVE-2026-7646: IBM Langflow OSS 1.0.0-dən 1.10.3-ə qədər versiyalarda server fayl sistemindən özbaşına fayl oxuma zəifliyi aşkarlanıb. Təcavüzkar, xüsusi hazırlanmış MCP `resources/read` sorğusu göndərərək digər istifadəçilərin sənədləri, JWT imza sirri, SQLite verilənlər bazası və proses mühiti dəyişənləri kimi həssas məlumatlara icazəsiz giriş əldə edə bilər.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: IBM
FAQ2
Which versions of IBM Langflow OSS are affected by CVE-2026-7646?
CVE-2026-7646 affects IBM Langflow OSS versions 1.0.0 through 1.10.3.
What sensitive data can an attacker access via CVE-2026-7646?
An attacker can gain unauthorized access to sensitive data such as other users' uploaded documents, the JWT signing secret, the SQLite database, and process environment variables.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.