CyberRota Analysis
AI-GeneratedIBM Langflow OSS versions 1.0.0 to 1.11.2 are susceptible to server-side request forgery (SSRF), which could enable authenticated attackers to issue unauthorized requests from the server. This vulnerability may lead to network enumeration or serve as a stepping stone for further attacks. Organizations using affected versions should prioritize remediation to mitigate potential security risks.
CVE
CVE-2026-12766
Severity
MEDIUM
CVSS
5.4
EPSS
0.18%
Original NVD Description
IBM Langflow OSS 1.0.0 through 1.11.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.