Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6599

22
FAUCET Score

BRIEFING NOTE: CVE-2026-6599 This vulnerability affects Langflow AI's Langflow application versions up to 1.8.3 and exists in the Model Context Protocol Configuration API component. The flaw stems from improper validation of the X-Forwarded-For HTTP header in the get_client_ip and install_mcp_config functions, allowing remote attackers to perform injection attacks through header manipulation. The vulnerability presents a medium severity risk with a CVSS score of 6.3, accessible remotely with low attack complexity and requiring only low privileges. Successful exploitation could result in limited confidentiality, integrity, and availability impacts. The EPSS score of 0.00041 indicates this threat ranks higher than approximately 99.9% of known vulnerabilities in terms of exploitation likelihood. Exploit code is publicly available and the vulnerability is currently listed on the CISA Known Exploited Vulnerabilities catalog as active, signaling real-world exploitation attempts. The vendor was notified early in the disclosure process but provided no response. Organizations running affected versions should prioritize assessment and patching efforts accordingly.

Impacted Technologies

VendorProductVersion(s)CPE
Langflow-AiLangflow
1.8.0, 1.8.1, 1.8.2, 1.8.3CNA affected

CVSS Data

CVSS version used by this source: 4.0

2.1LOW

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
LOW
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.23%
Probability of exploitation in next 30 days
EPSS Percentile
14.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0023 is in the 15th percentile among its peer group of 21,974 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

pipGHSA-v66p-f7x3-4794low

Langflow vulnerable to injection

Apr 20, 2026

References

gist.github.com / chenhouser2025/a909c47316b7a0948ee68c109ab747a3
vuldb.com / submit/791922
vuldb.com / vuln/358234
vuldb.com / vuln/358234/cti