CVE-2026-9186 | IBM Langflow up to 1.11.2 MCP Configuration .cursor/mcp.json X-Forwarded-For access control
A vulnerability, which was classified as problematic, was found in IBM Langflow up to 1.11.2. Affected is an unknown function of the file .cursor/mcp.json of the component MCP Configuration Handler. Executing a manipulation of the argument X-Forwarded-For can lead to improper access controls.
This vulnerability appears as CVE-2026-9186. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More