EXPOSURES › CVE-2026-7663
CVE-2026-7663
CRITICAL
DETAIL
SourceNVD · cve
Published2026-06-30
CVSS9.1
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-7663 ↗
SHAME 35/100
IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.
▸ RECOMMENDED ACTION Critical severity — schedule patching of the affected products.
PLAYERS IMPLICATED
DESCRIPTION
IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.