Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105698— Langflow: Cross-user flow access and vertex execution via deprecated /api/v1/build/{flow_id}/vertices endpoints

Quick assessment

Affected
langflow-ai langflow
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Langflow 是一款用于构建和部署 AI 驱动的智能体(agents)和工作流的工具。在版本 1.0.0 至 1.10.1 期间,Langflow 未在已弃用的 API 端点 和 中验证流程(flow)的所有权。 在版本 1.7.1 及更早版本中,未经身份验证的攻击者只要知道其他用户的流程 UUID,即可访问上述端点;从版本 1.7.2 至 1.10.0 开始,调用者虽需进行身份验证,但无需具备特殊权限。通过此类访问,攻击者可以调用 来加载并缓存私有流程图,枚举其节点(vertex)标识符,并利用 执行选定的节

CVSS 5.4 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105698

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Langflow: Cross-user flow access and vertex execution via deprecated /api/v1/build/{flow_id}/vertices endpoints
Source: CVE Program / CVE List V5
Vulnerability Description
Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.0.0 until 1.10.1, Langflow did not verify flow ownership in the deprecated POST /api/v1/build/{flow_id}/vertices and POST /api/v1/build/{flow_id}/vertices/{vertex_id} handlers. Through version 1.7.1, an unauthenticated caller who knew another user's flow UUID could reach these handlers; from version 1.7.2 through 1.10.0, callers had to authenticate but needed no elevated privileges. Such a caller could cause retrieve_vertices_order to load and cache the private graph, enumerate its vertex identifiers, and use build_vertex to execute selected vertices and receive their results. build_graph_from_db_no_cache performed a primary-key lookup without an owner filter. This could disclose private flow structure, configured values, and selected outputs and could trigger victim-configured side effects and build-history records, although it did not expose the victim's variable-store credentials or permit modification of the stored flow. This issue is fixed in Langflow 1.10.1 and langflow-base 0.10.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
langflow-ai langflow >= 1.0.0, < 1.10.1 -
langflow-ai langflow-base < 0.10.1 -

II. Public POCs for CVE-2026-105698

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105698

请登录查看更多情报信息。

Other References for CVE-2026-105698 (4)

Same Patch Batch · langflow-ai · 2026-10-05 · 5 CVEs total

CVE-2026-105697 9.9 CRITICAL Langflow: OS command injection (RCE) via arbitrary command in MCP stdio server configurati
CVE-2026-105740 9.9 CRITICAL Langflow: Authenticated RCE via MCP Stdio transport allows any user to execute arbitrary O
CVE-2026-105699 7.1 HIGH Langflow: Authenticated Cross-Project File Disclosure via Unscoped MCP Resource Handlers
CVE-2026-105741 7.1 HIGH Langflow: IP Spoofing Bypass via `X-Forwarded-For` Allowing Remote Configuration Write

IV. Related Vulnerabilities

V. Comments for CVE-2026-105698

No comments yet


Leave a comment