CVE-2026-5025
MEDIUMLangflow - Application Logs Exposed to All Authenticated Users
Title source: cnaDescription
The '/logs' and '/logs-stream' endpoints in the log router allow any authenticated user to read the full application log buffer. These endpoints only require basic authentication ('get_current_active_user') without any privilege checks (e.g., 'is_superuser').
References (1)
Core 1
Core References
Scores
CVSS v3
6.5
EPSS
0.0026
EPSS Percentile
16.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-862
Status
published
Products (2)
langflow/langflow
langflow-ai/langflow
Published
Mar 27, 2026
Tracked Since
Mar 29, 2026