Impact
Langflow versions from 1.0.0 through 1.10.1 allowed callers to use the deprecated POST /api/v1/build/{flow_id}/vertices and POST /api/v1/build/{flow_id}/vertices/{vertex_id} endpoints without verifying that the caller owned the target flow. The vulnerability permits a user, who knows another’s flow UUID, to retrieve the flow’s internal graph structure, enumerate vertex identifiers, and trigger execution of selected vertices. The impact includes exposure of private flow configurations, selected outputs, and the potential to cause side effects defined by the victim’s workflow. The weakness is clearly an authorization bypass as described by CWE-639 and CWE-862, enabling unauthorized read and execution of protected resources. The CVSS score of 5.4 indicates a moderate impact, but the exposed data and execution capability represent significant privacy and integrity concerns.
Affected Systems
The affected products are langflow‑ai:langflow and langflow‑ai:langflow‑base. All releases up to and including langflow 1.10.1 and langflow‑base 0.10.1, but not the patch releases that follow, are vulnerable. This includes every major and minor build from the earliest 1.0.0 release until the versioned fixes were applied.
Risk and Exploitability
The vulnerability is reachable via the web API, meaning it requires network access to the Langflow instance. An attacker can leverage knowledge of a target flow’s UUID and, if the instance requires authentication (post‑1.7.2), basic credentials that grant read access. The EPSS score is not available, and the flaw is not listed in CISA’s KEV catalog, suggesting an uncertain but non‑negligible attack frequency. The CVSS score of 5.4 reflects moderate severity, but the fact that the flaw can expose sensitive configuration and trigger arbitrary execution increases risk for both privacy and availability attacks. Reducing access to the deprecated endpoints and ensuring ownership checks are in place are essential to mitigate this exploitable weakness.
OpenCVE Enrichment