CVE-2026-9130 | IBM Langflow OSS up to 1.10.3 MemoryComponent session_id authorization
A vulnerability classified as problematic has been found in IBM Langflow OSS up to 1.10.3. This issue affects the function MemoryComponent.retrieve_messages/ MemoryComponent.store_message of the component MemoryComponent. The manipulation of the argument session_id leads to authorization bypass.
This vulnerability is uniquely identified as CVE-2026-9130. The attack is possible to be carried out remotely. No exploit exists.VulDB Recent EntriesRead More