MediumVulnerability
CVE-2026-105698: Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.0.0 until 1.10.1, Langflow did…
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-105698
- Published
- Record updated
Summary
Langflow versions 1.0.0 through 1.10.1 did not verify flow ownership in the deprecated POST /api/v1/build/{flow_id}/vertices and POST /api/v1/build/{flow_id}/vertices/{vertex_id} handlers. Through 1.7.1, an unauthenticated caller who knew another user's flow UUID could reach them; from 1.7.2 through 1.10.0, any authenticated caller without elevated privileges could. The caller could load and cache a private graph, enumerate its vertices, and execute selected vertices to receive their results, disclosing flow structure, configured values and outputs, and triggering victim-configured side effects. Variable-store credentials could not be exposed and the stored flow could not be modified.
Mitigation
Fixed in Langflow 1.10.1 and langflow-base 0.10.1.
Related items
- CriticalCVE-2026-108263: Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow coSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database
- CriticalGHSA-9mp3-24cc-77mg: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool CallsSimilar attack · GitHub Advisory Database