Multiple vulnerabilities in IBM ContextForge and Langflow OSS
IBM ContextForge MCP Gateway and Langflow OSS 1.0.0-1.11.2 contain multiple vulnerabilities including server-side request forgery, authentication bypass, arbitrary file writes, path traversal, stored XSS, and remote code execution affecting authenticated attackers.
Disclosed 4 September 2026 · Record updated 13 September 2026
Impact
Remote authenticated attackers can obtain sensitive information, bypass security controls, write arbitrary files, execute code, and modify IDE configurations in affected systems.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-77822
- github.comhttps://github.com/advisories/GHSA-gqfh-c8pj-64mr
- github.comhttps://github.com/advisories/GHSA-342j-xgq4-rg29
- github.comhttps://github.com/advisories/GHSA-44jp-wv2q-qjwp
- github.comhttps://github.com/advisories/GHSA-rj5m-gxpg-4hwq
- github.comhttps://github.com/advisories/GHSA-qjf8-5fwj-jhh8
