Описание
IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 1.0.0 (включая) до 1.10.0 (исключая)
cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*
EPSS
Процентиль: 26%
0.00328
Низкий
9.1 Critical
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-285
CWE-863
Связанные уязвимости
CVSS3: 9.1
github
около 2 месяцев назад
IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.
EPSS
Процентиль: 26%
0.00328
Низкий
9.1 Critical
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-285
CWE-863