CVE Vulnerabilities

CVE-2026-13444

.NET Misconfiguration: Use of Impersonation

Published: Jul 30, 2026 | Modified: Aug 04, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another users private vector documents by creating their own flow with matching Chroma persist_directory and collection_name values. The attacker receives exact victim content in their workflow output despite having no authorization to read the victims flow. Additionally, the attacker can pollute the victims collection by inserting their own documents into the shared namespace.

Weakness

Allowing a .NET application to run at potentially escalated levels of access to the underlying operating and file systems can be dangerous and result in various forms of attacks.

Affected Software

NameVendorStart VersionEnd Version
LangflowLangflow1.0.0 (including)1.10.2 (excluding)

Potential Mitigations

References