CVE-2026-12763
בינונית 4.2
תיאור (מקור, אנגלית)
IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context due to improper cache key isolation in the MCP Tools component.
מדדים
- CVSS 3.1
-
4.2 (MEDIUM)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-1/10/2026
- CWE
- CWE-306