CVE Vulnerabilities

CVE-2026-13442

.NET Misconfiguration: Use of Impersonation

Published: Jul 28, 2026 | Modified: Aug 04, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another users FAISS namespace to access owner-only vector content and influence later query results. This causes cross-user information disclosure and limited integrity impact through persistent poisoning of returned results.

Weakness

Allowing a .NET application to run at potentially escalated levels of access to the underlying operating and file systems can be dangerous and result in various forms of attacks.

Affected Software

NameVendorStart VersionEnd Version
LangflowLangflow1.0.0 (including)1.10.2 (excluding)

Potential Mitigations

References