Description
Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.0.0 until 1.10.1, Langflow did not verify flow ownership in the deprecated POST /api/v1/build/{flow_id}/vertices and POST /api/v1/build/{flow_id}/vertices/{vertex_id} handlers. Through version 1.7.1, an unauthenticated caller who knew another user's flow UUID could reach these handlers; from version 1.7.2 through 1.10.0, callers had to authenticate but needed no elevated privileges. Such a caller could cause retrieve_vertices_order to load and cache the private graph, enumerate its vertex identifiers, and use build_vertex to execute selected vertices and receive their results. build_graph_from_db_no_cache performed a primary-key lookup without an owner filter. This could disclose private flow structure, configured values, and selected outputs and could trigger victim-configured side effects and build-history records, although it did not expose the victim's variable-store credentials or permit modification of the stored flow. This issue is fixed in Langflow 1.10.1 and langflow-base 0.10.1.
Published: 2026-10-05
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized data disclosure and execution of arbitrary workflow vertices
Action: Immediate Patch
AI Analysis

Impact

Langflow versions from 1.0.0 through 1.10.1 allowed callers to use the deprecated POST /api/v1/build/{flow_id}/vertices and POST /api/v1/build/{flow_id}/vertices/{vertex_id} endpoints without verifying that the caller owned the target flow. The vulnerability permits a user, who knows another’s flow UUID, to retrieve the flow’s internal graph structure, enumerate vertex identifiers, and trigger execution of selected vertices. The impact includes exposure of private flow configurations, selected outputs, and the potential to cause side effects defined by the victim’s workflow. The weakness is clearly an authorization bypass as described by CWE-639 and CWE-862, enabling unauthorized read and execution of protected resources. The CVSS score of 5.4 indicates a moderate impact, but the exposed data and execution capability represent significant privacy and integrity concerns.

Affected Systems

The affected products are langflow‑ai:langflow and langflow‑ai:langflow‑base. All releases up to and including langflow 1.10.1 and langflow‑base 0.10.1, but not the patch releases that follow, are vulnerable. This includes every major and minor build from the earliest 1.0.0 release until the versioned fixes were applied.

Risk and Exploitability

The vulnerability is reachable via the web API, meaning it requires network access to the Langflow instance. An attacker can leverage knowledge of a target flow’s UUID and, if the instance requires authentication (post‑1.7.2), basic credentials that grant read access. The EPSS score is not available, and the flaw is not listed in CISA’s KEV catalog, suggesting an uncertain but non‑negligible attack frequency. The CVSS score of 5.4 reflects moderate severity, but the fact that the flaw can expose sensitive configuration and trigger arbitrary execution increases risk for both privacy and availability attacks. Reducing access to the deprecated endpoints and ensuring ownership checks are in place are essential to mitigate this exploitable weakness.

Generated by OpenCVE AI on October 5, 2026 at 22:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to langflow 1.10.1 or langflow‑base 0.10.1 to obtain the fix that enforces flow ownership checks on the deprecated vertex endpoints.
  • Disable or remove the deprecated /api/v1/build/{flow_id}/vertices and /api/v1/build/{flow_id}/vertices/{vertex_id} endpoints from the production deployment if they are no longer needed, or apply strict authentication and authorization policies to restrict them to flow owners only.
  • Verify that all API endpoints have appropriate ownership and privilege checks in place; any future customizations involving graph construction must filter by the authenticated user to prevent similar bypasses.

Generated by OpenCVE AI on October 5, 2026 at 22:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
Description Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.0.0 until 1.10.1, Langflow did not verify flow ownership in the deprecated POST /api/v1/build/{flow_id}/vertices and POST /api/v1/build/{flow_id}/vertices/{vertex_id} handlers. Through version 1.7.1, an unauthenticated caller who knew another user's flow UUID could reach these handlers; from version 1.7.2 through 1.10.0, callers had to authenticate but needed no elevated privileges. Such a caller could cause retrieve_vertices_order to load and cache the private graph, enumerate its vertex identifiers, and use build_vertex to execute selected vertices and receive their results. build_graph_from_db_no_cache performed a primary-key lookup without an owner filter. This could disclose private flow structure, configured values, and selected outputs and could trigger victim-configured side effects and build-history records, although it did not expose the victim's variable-store credentials or permit modification of the stored flow. This issue is fixed in Langflow 1.10.1 and langflow-base 0.10.1.
Title Langflow: Cross-user flow access and vertex execution via deprecated /api/v1/build/{flow_id}/vertices endpoints
Weaknesses CWE-639
CWE-862
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-05T20:20:27.287Z

Reserved: 2026-10-05T17:48:58.627Z

Link: CVE-2026-105698

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T21:16:35.257

Modified: 2026-10-05T21:16:35.257

Link: CVE-2026-105698

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T22:45:18Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key

  • CWE-862

    Missing Authorization