CVE-2026-7872
גבוהה 8.1
תיאור (מקור, אנגלית)
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication tokens for any user.
מדדים
- CVSS 3.1
-
8.1 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-3/8/2026
- CWE
- CWE-22
מוצרים מושפעים
langflow: langflow; apple: macos; linux: linux kernel; microsoft: windows
קישורים
- https://www.ibm.com/support/pages/node/7278934 Vendor Advisory