Langflow Langflow — CVE-2026-7663 (Critical)

Date Jun 30, 2026
Type Vendor advisory
Signal Critical vendor advisory
Vendor / Product Langflow · Langflow
CVE CVE-2026-7663
Critical vendor advisory CVE-2026-7663

Summary

IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.

Why it matters

This CVE carries a CRITICAL severity rating (CVSS 9.1) in Langflow Langflow. Patch or mitigate promptly. EPSS percentile: 15%.

Operator check

Review CVE-2026-7663 in your asset inventory. Apply patches per vendor guidance and verify Langflow is not exposed. CVSS score: 9.1. EPSS probability: 0.2%; percentile: 15%.

Sources

PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.