IBM Langflow OSS是美国IBM公司的一个开源的低代码可视化AI工作流构建工具,它让开发者能通过拖拽组件的方式快速搭建、部署和迭代AI智能体与RAG应用,同时支持用Python进行深度定制以集成企业系统。 IBM Langflow OSS 1.0.0版本至1.10.1版本存在配置错误漏洞,该漏洞源于允许攻击者重用其他用户的FAISS命名空间,可导致跨用户信息泄露和有限完整性影响。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IBM | Langflow OSS | 1.0.0≤ 1.10.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | Langflow OSS | 1.0.0 ~ 1.10.1 |
cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-14446 | 9.8 CRITICAL | IBM WebSphere Application Server is affected by a privilege escalation |
| CVE-2026-14512 | 9.8 CRITICAL | IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of |
| CVE-2026-14973 | 9.3 CRITICAL | Path Traversal in IBM Desktop App |
| CVE-2026-14958 | 9.1 CRITICAL | OS command injection in IBM Aspera Faspex |
| CVE-2026-14959 | 9.1 CRITICAL | OS Command Injection in IBM Aspera Faspex |
| CVE-2026-15064 | 8.7 HIGH | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by |
| CVE-2026-15325 | 8.7 HIGH | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by |
| CVE-2026-14996 | 8.2 HIGH | Multiple vulnerabilities in IBM Aspera Faspex |
| CVE-2026-7769 | 8.1 HIGH | SQL injection Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File |
| CVE-2026-14974 | 8.1 HIGH | IBM WebSphere Application Server is affected by cross-site scripting and deserialization v |
| CVE-2026-13463 | 7.5 HIGH | Due to use of IBM Storage Protect, IBM Cloud Pak System is affected by vulnerability [] |
| CVE-2026-14981 | 7.5 HIGH | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by |
| CVE-2026-15057 | 7.5 HIGH | IBM WebSphere Application Server Liberty is affected by a denial of service vulnerability |
| CVE-2026-15280 | 7.5 HIGH | IBM WebSphere Application Server Liberty is affected by a remote code execution and path-s |
| CVE-2026-15328 | 7.4 HIGH | IBM WebSphere Application Server and WebSphere Application Server Liberty is inconsistent |
| CVE-2026-14528 | 7.4 HIGH | IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of |
| CVE-2026-14893 | 7.3 HIGH | IBM Instana Observability is affected by multiple Prototype Pollution within Instana Agent |
| CVE-2026-16192 | 7.1 HIGH | IBM WebSphere Application Server Liberty is affected by a denial of service |
| CVE-2026-14976 | 7.1 HIGH | IBM WebSphere Application Server Liberty is affected by a remote code execution and path-s |
| CVE-2026-16184 | 7.0 HIGH | IBM WebSphere Application Server is affected by an authentication bypass |
Showing top 20 of 31 CVEs. View all on vendor page → →
No comments yet