← Zurück zur CVE-Suche

CVE-2026-33760

Langflow

Beschreibung

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow-s /api/v1/monitor router exposes 7 endpoints that perform read, write, and delete operations on user-owned resources — messages, sessions, build artifacts, and LLM transaction logs — without verifying that the authenticated requester owns the targeted resource. Any authenticated user can read, modify, rename, or permanently delete another user-s data by supplying the target-s resource ID or flow_id. This is a classic IDOR/BOLA vulnerability. Notably, the same source file (monitor.py) contains one correctly-implemented endpoint that uses an ownership check, demonstrating the correct pattern was known but inconsistently applied. This vulnerability is fixed in 1.9.0.

CVSS 8.8EPSS 0.357%Risiko 0.91
Quelle öffnen
Veröffentlicht
2026-06-23 17:16:52
Betroffene Versionen
<1.9.0
Typ
Kritische Software
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H