Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8c4j-f57c-35cf | Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check |
Mon, 11 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:langflow:langflow-base:*:*:*:*:*:python:*:* cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* cpe:2.3:a:langflow:langflow:1.5.0:dev0:*:*:*:*:*:* cpe:2.3:a:langflow:langflow:1.5.0:dev1:*:*:*:*:*:* |
|
| Metrics |
cvssV3_1
|
Tue, 31 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 30 Mar 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Langflow
Langflow langflow Langflow langflow-base |
|
| Vendors & Products |
Langflow
Langflow langflow Langflow langflow-base |
Fri, 27 Mar 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.5.1, the `_read_flow` helper in `src/backend/base/langflow/api/v1/flows.py` branched on the `AUTO_LOGIN` setting to decide whether to filter by `user_id`. When `AUTO_LOGIN` was `False` (i.e., authentication was enabled), neither branch enforced an ownership check — the query returned any flow matching the given UUID regardless of who owned it. This allowed any authenticated user to read any other user's flow, including embedded plaintext API keys; modify the logic of another user's AI agents, and/or delete flows belonging to other users. The vulnerability was introduced by the conditional logic that was meant to accommodate public/example flows (those with `user_id = NULL`) under auto-login mode, but inadvertently left the authenticated path without an ownership filter. The fix in version 1.5.1 removes the `AUTO_LOGIN` conditional entirely and unconditionally scopes the query to the requesting user. | |
| Title | Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check | |
| Weaknesses | CWE-639 CWE-862 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-01T03:55:31.834Z
Reserved: 2026-03-25T15:29:04.745Z
Link: CVE-2026-34046
Updated: 2026-03-31T13:57:14.353Z
Status : Analyzed
Published: 2026-03-27T21:17:27.753
Modified: 2026-05-11T14:23:34.330
Link: CVE-2026-34046
No data.
OpenCVE Enrichment
Updated: 2026-03-30T07:59:25Z
Github GHSA