<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 15:31:17 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-7663 — Unauthenticated Cross-User MCP Resource Access and Tool Execution via Streamable Transport Authorization Bypass</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-7663</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; IBM Langflow OSS&lt;/p&gt;
&lt;p&gt;IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; IBM Langflow OSS&lt;/p&gt;
&lt;p&gt;IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-7663</guid>
    </item>
  </channel>
</rss>
