Impact
The vulnerability allows an authenticated attacker to run flows and access sensitive data because API keys issued to deactivated users do not expire. This defect in session handling effectively bypasses authentication controls, permitting the attacker to reuse valid credentials and execute unauthorized operations. The weakness is categorized as CWE‑613, an authentication mechanism flaw.
Affected Systems
IBM Langflow OSS versions 1.0.0 through 1.11.5 are affected. Users relying on API key authentication in any of these releases must upgrade or otherwise ensure keys are properly revoked. The vulnerability spans all deployments that use the default session expiration logic of these versions.
Risk and Exploitability
With a CVSS score of 8.1 the vulnerability is considered high severity. The EPSS score is not available and the flaw is not listed in the CISA KEV catalog, indicating no confirmed exploitation yet. Nevertheless, if an attacker can obtain an API key tied to a deactivated account, the key can be reused before any perceived expiration, allowing the attacker to execute flows and exfiltrate confidential data. The impact is limited to the scope of the compromised account’s permissions but could allow further lateral movement if embedded within broader automation workflows.
OpenCVE Enrichment