{"data":{"id":"051270ac-41e7-4b62-b655-2ca3afb01fe1","title":"CVE-2026-105698: Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.0.0 until 1.10.1, Langflow did…","summary":"Langflow versions 1.0.0 through 1.10.1 did not verify flow ownership in the deprecated POST /api/v1/build/{flow_id}/vertices and POST /api/v1/build/{flow_id}/vertices/{vertex_id} handlers. Through 1.7.1, an unauthenticated caller who knew another user's flow UUID could reach them; from 1.7.2 through 1.10.0, any authenticated caller without elevated privileges could. The caller could load and cache a private graph, enumerate its vertices, and execute selected vertices to receive their results, disclosing flow structure, configured values and outputs, and triggering victim-configured side effects. Variable-store credentials could not be exposed and the stored flow could not be modified.","solution":"Fixed in Langflow 1.10.1 and langflow-base 0.10.1.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105698","publishedAt":"2026-10-05T21:16:35.257Z","cveId":"CVE-2026-105698","cweIds":["CWE-639","CWE-862"],"cvssScore":"5.4","cvssSeverity":"medium","severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":["langflow@>= 1.0.0, < 1.10.1 (fixed: 1.10.1)","langflow-base@< 0.10.1 (fixed: 0.10.1)"],"affectedPackageNames":["langflow","langflow-base"],"affectedVendors":[],"affectedVendorsRaw":["Langflow"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":"Langflow flow ownership bypass in deprecated build vertices endpoints","headlinePromptVersion":"h1","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00177,"epssCheckedAt":"2026-10-10T03:00:36.826Z","kevDateAdded":null,"advisoryAliases":["GHSA-gh98-4phw-6fmw"],"affectedPackagesSource":"ghsa","affectedPackagesCheckedAt":"2026-10-10T03:42:58.059Z","patchAvailable":true,"disclosureDate":"2026-10-05T21:16:35.257Z","capecIds":["CAPEC-122"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}