Vulnerability PYSEC-2026-2567

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
2 months ago
July 13, 2026 at 02:36 PM UTC
Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check
0.0.31 - 1.5.0.post2
0.0.31 - 1.5.0.post2

Summary

Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check

Details

Vulnerability

IDOR in GET/PATCH/DELETE /api/v1/flow/{flow_id}

The _read_flow helper in src/backend/base/langflow/api/v1/flows.py branched on the AUTO_LOGIN setting to decide whether to filter by user_id. When AUTO_LOGIN was False (i.e., authentication was enabled), neither branch enforced an ownership check — the query returned any flow matching the given UUID regardless of who owned it.

This exposed any authenticated user to:

  • Read any other user's flow, including embedded plaintext API keys
  • Modify the logic of another user's AI agents
  • Delete flows belonging to other users

The vulnerability was introduced by the conditional logic that was meant to accommodate public/example flows (those with user_id = NULL) under auto-login mode, but inadvertently left the authenticated path without an ownership filter.

Acknowledgements

Langflow thanks the security researcher who responsibly disclosed this vulnerability:

Impacted packages

Timeline

Published
2 months ago
July 13, 2026 at 02:36 PM UTC
Fixed (1.5.1)
1 year ago
August 28, 2025 at 04:10 PM UTC
Last Modified
2 months ago
July 13, 2026 at 04:43 PM UTC