Summary
CVE-2026-10560 is a missing authentication vulnerability (CWE-287) in IBM Langflow OSS versions 1.0.0 through 1.9.6, carrying a CVSS v3.1 base score of 8.2 (High). The flaw affects the /api/v1/build_public_tmp/ API endpoint family, allowing unauthenticated, network-accessible attackers to read sensitive build event data or cancel in-flight build jobs without any credentials or user interaction. With thousands of Langflow instances directly exposed to the internet, this vulnerability poses a significant risk of sensitive data leakage to any organization running an unpatched deployment.
Technical details
- Root cause: Missing authentication controls (CWE-287 – Improper Authentication) on two endpoints within the
/api/v1/build_public_tmp/family; the endpoints perform no authentication checks and no access control validation on incoming requests. - Affected endpoints:
GET /api/v1/build_public_tmp/{job_id}/events— streams live build event data, which can include customer prompts, LLM responses, API keys, internal documents from RAG pipelines, and server-side Python tracebacks.POST /api/v1/build_public_tmp/{job_id}/cancel— cancels in-flight build jobs, enabling disruption of workflow execution.
- Trigger conditions: Exploitation requires only a valid job identifier; no authentication token or privileged account is needed. The identifier can be obtained through reconnaissance or enumeration.
- Attack vector: Fully network-accessible with no privileges required and no user interaction required (AV:N/AC:L/PR:N/UI:N).
- Impact: High confidentiality impact through unauthorized exposure of sensitive build event data; low integrity impact through unauthorized cancellation of running jobs.
Affected software
- IBM Langflow OSS versions 1.0.0 through 1.9.6
Severity
- CVSS v3.1 Base Score: 8.2 (High)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N - CWE: CWE-287 – Improper Authentication
Mitigation and recommended actions
- Immediate action: Upgrade to IBM Langflow OSS version 1.10.0, which contains the vendor-provided fix. The patched package is available at pypi.org/project/langflow/.
- No workarounds identified: IBM has not published alternative mitigations for this vulnerability. Organizations unable to patch immediately should restrict network access to Langflow instances and block unauthenticated external access to the
/api/v1/build_public_tmp/endpoint family at the network or reverse-proxy layer as a temporary defensive measure.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

