Description
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.7.0, the logout button does not clear the session. The previous user stays logged in unless another user explicitly logs in. This vulnerability is fixed in 1.7.0.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/langflow-ai/langflow/security/advisories/GHSA-7hw8-6q6r-4276
X_Refsource_Misc x_refsource_misc
https://github.com/langflow-ai/langflow/pull/10527
X_Refsource_Misc x_refsource_misc
https://github.com/langflow-ai/langflow/pull/10528
Scores
CVSS v3
6.1
EPSS
0.0019
EPSS Percentile
8.8%
Attack Vector
PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-613
Status
published
Products (2)
langflow/langflow
< 1.7.0
langflow-ai/langflow
< 1.7.0
Published
Jun 23, 2026
Tracked Since
Jun 23, 2026