Impact
Langflow permitted authenticated users to access file resources that were not bound to their own project. The application accepted a URI for a resource to be read, parsed a flow identifier and filename, and forwarded the request to the storage service without checking that the flow actually belonged to the authenticated user or the current project. This authorization bypass allows the attacker to read any other user’s flow‑backed files, such as uploaded documents, structured data, and prompts, without modifying them. The vulnerability is a classic example of CWE‑639 – Authorization Bypass Through User‑Controlled Key.
Affected Systems
The vulnerability affects Langflow AI’s Langflow application, versions 1.6.8 through 1.9.1. Any deployment running a version in this range that exposes project‑scoped MCP endpoints is vulnerable.
Risk and Exploitability
The CVSS score is 7.1, indicating a high‑severity risk. Although an EPSS score is not available, the flaw is not listed in the CISA KEV catalog. The attack path requires an authenticated user with access to any project‑scoped MCP endpoint, a scenario that is likely to exist in multi‑tenant deployments. Because the vulnerability discloses private flow artifacts, the potential damage to confidentiality is significant, while no integrity or availability impact is noted. The exploit is straightforward for any authenticated user who can specify a target flow ID and filename.
OpenCVE Enrichment