{"data":{"id":"bc3f64bf-002c-43f6-9e92-bccba1a8ff58","title":"CVE-2026-105699: Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.6.8 until 1.9.1, Langflow…","summary":"Langflow versions from 1.6.8 through 1.9.1 fail to authorize the resource URI passed to resources/read on project-scoped MCP connections. An authenticated user with access to any project-scoped MCP endpoint can read another user's flow-backed files, including uploaded documents, structured data, prompts and other private flow artifacts. Global handle_list_resources and handle_list_tools behavior can also disclose the flow and file identifiers needed to target them. Victim files and stored flows are not modified.","solution":"Fixed in 1.9.1.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105699","publishedAt":"2026-10-05T21:16:35.410Z","cveId":"CVE-2026-105699","cweIds":["CWE-639"],"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["data_extraction"],"issueType":"vulnerability","affectedPackages":["langflow@>= 1.6.8, <= 1.9.0 (fixed: 1.9.1)"],"affectedPackageNames":["langflow"],"affectedVendors":[],"affectedVendorsRaw":["Langflow"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":"Langflow MCP resource read exposes other users' flow files","headlinePromptVersion":"h1","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00246,"epssCheckedAt":"2026-10-10T02:56:51.777Z","kevDateAdded":null,"advisoryAliases":["GHSA-4hmc-cfm3-w43c"],"affectedPackagesSource":"ghsa","affectedPackagesCheckedAt":"2026-10-10T03:42:57.502Z","patchAvailable":true,"disclosureDate":"2026-10-05T21:16:35.410Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}