What is CVE-2026-9130?
An authorization bypass vulnerability exists in IBM Langflow OSS versions 1.0.0 through 1.10.3. The flaw in the MemoryComponent allows authenticated users to access other users' chat history via session_id collision, as the retrieve_messages and store_message methods filter on session_id without proper validation.
Azərbaycanca: IBM Langflow OSS 1.0.0-dən 1.10.3-ə qədər versiyalarda avtorizasiya bypass zəifliyi aşkarlanıb. Bu, autentifikasiya olunmuş istifadəçilərə MemoryComponent-də session_id toqquşması vasitəsilə digər istifadəçilərin çat tarixçəsinə giriş imkanı verir.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: IBM
FAQ1
Under what conditions can the CVE-2026-9130 vulnerability in IBM Langflow OSS be exploited?
This authorization bypass vulnerability allows authenticated users to access other users' chat history via session_id collision in the MemoryComponent.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.