Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gqfh-c8pj-64mr

Опубликовано: 04 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 header, enabling arbitrary writes to IDE config files (~/.cursor/mcp.json, etc.).

IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 header, enabling arbitrary writes to IDE config files (~/.cursor/mcp.json, etc.).

EPSS

Процентиль: 19%
0.00271
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 6.5
nvd
15 дней назад

IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 header, enabling arbitrary writes to IDE config files (~/.cursor/mcp.json, etc.).

EPSS

Процентиль: 19%
0.00271
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-284