Langflow Langflow Vulnerability
Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request.
CVSS Score
9.8
CRITICAL
Published
07 Jul 2026 00:00
Modified
N/A
Vendor
Langflow
Product
Langflow
Source
CIRCL
Affected Versions
Fix
Vendor Patch / Mitigation Available
Weaknesses (CWE)
CWE-639
Affected Systems
Langflow
Langflow
Langflow
Langflow
External Links
KEV Status
Known Exploited Vulnerability