Showing 1 vulnerability on this page for langflow-base

Signals CISA KEV Ransomware Nuclei
langflow-ai vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.5.1, the `_read_flow` helper in `src/backend/base/langflow/api/v1/flows.py` branched on the `AUTO_LOGIN` setting to decide whether to filter by `user_id`. When `AUTO_LOGIN` was `False` (i.e., authentication was enabled), neither branch enforced an ownership check — the query returned any flow matching the given UUID regardless of who owned it. This allowed any authenticated user to read any other us

CWE-639CWE-862Mar 27, 2026
CVSS8.7v4.0EPSS0.468%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX