HighVulnerability
CVE-2026-105699: Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.6.8 until 1.9.1, Langflow…
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-105699
- Published
- Record updated
Summary
Langflow versions from 1.6.8 through 1.9.1 fail to authorize the resource URI passed to resources/read on project-scoped MCP connections. An authenticated user with access to any project-scoped MCP endpoint can read another user's flow-backed files, including uploaded documents, structured data, prompts and other private flow artifacts. Global handle_list_resources and handle_list_tools behavior can also disclose the flow and file identifiers needed to target them. Victim files and stored flows are not modified.
Mitigation
Fixed in 1.9.1.
Topics
Related items
- HighGHSA-6wjp-v33h-5cvq: PraisonAI: AgentOS defaults to network-exposed no-auth mode, allowing unauthenticated agent invocation and instruction disclosureSimilar attack · GitHub Advisory Database
- HighCVE-2026-101998: Docker Sandboxes could fail open while masking credentials in protected proxy responses. When a response-body read…Similar attack · NVD/CVE Database
- MediumEncrypted instructions trick Copilot CLI into spilling developer secretsSimilar attack · CSO Online
- HighCVE-2026-93677: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due…Similar attack · NVD/CVE Database
- HighCVE-2026-101331: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due…Similar attack · NVD/CVE Database