Skip to content
IBMCVE-2026-13444

IBM Langflow OSS: attacker could access another user's private vector

High8.1CVE-2026-13444 · Published Jul 30, 2026 · updated Aug 4, 2026

IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents by creating their own flow with matching Chroma persist_directory and collection_name values. The attacker receives exact victim content in their workflow output despite having no authorization to read the victim's flow. Additionally, the attacker can pollute the victim's collection by inserting their own documents into the shared namespace.

IBM advisory

Affected versions

PackageAffectedFixed in
Langflow OSS
Product
>= 1.0.0, <= 1.10.1No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Severity from
CISA (its enrichment of the CVE record)
Weakness
CWE-520

More IBM advisories

All IBM
Advisory
IBM WebSphere Application Server: remote code execution
High8.5Jul 30
IBM Langflow OSS: code injection
Critical9.9Jul 30
UCD - IBM: information disclosure
Medium4.3Jul 30
IBM Langflow OSS: improper input validation
Critical9.9Jul 30
IBM Langflow OSS: path traversal
High7.5Jul 30
IBM HMC: remote code execution
Critical9.8Jul 30

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.