What is CVE-2026-9077?
CVE-2026-9077 affects IBM Langflow OSS versions 1.0.0 through 1.10.3. The vulnerability allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations to IDE configuration files on the host system. Affected users should update to the latest patched version immediately.
Azərbaycanca: CVE-2026-9077, IBM Langflow OSS-in 1.0.0-dən 1.10.3-ə qədər versiyalarında aşkarlanıb. Bu boşluq uzaqdan autentifikasiya olunmuş hücumçuya yalnız localhost məhdudiyyətlərini keçərək host sistemdə IDE konfiqurasiya fayllarına özbaşına MCP server konfiqurasiyaları yazmağa imkan verir. Sistem sahibləri proqramı ən son versiyaya yeniləməlidir.
Related CVEs
link basis: shared vendor: IBM
FAQ2
Can CVE-2026-9077 be exploited only by attackers on the local network?
No, this vulnerability allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations to IDE configuration files on the host system.
Which versions of IBM Langflow OSS are affected by CVE-2026-9077?
This vulnerability affects IBM Langflow OSS versions 1.0.0 through 1.10.3.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.