CVE-2026-12763

Summary

IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context due to improper cache key isolation in the MCP Tools component.

Affected Software

VendorProductVersion RangeStatus
IBMLangflow OSS1.0.0 <= 1.11.5affected

Weaknesses

  • CWE-306: CWE-306 Missing Authentication for Critical Function

References