Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Dhirajranka

#50887of 57,577
5.4Total CVSS
Vulnerabilities · 1
PT-2026-106233
5.4
2026-10-05
Langflow · Langflow · CVE-2026-105698
**Name of the Vulnerable Software and Affected Versions** Langflow versions 1.0.0 through 1.10.0 **Description** Langflow fails to verify flow ownership in the deprecated 'POST /api/v1/build/{flow id}/vertices' and 'POST /api/v1/build/{flow id}/vertices/{vertex id}' endpoints. In versions prior to 1.7.2, these handlers could be accessed by unauthenticated callers. In versions 1.7.2 through 1.10.0, authenticated users without elevated privileges could access them. An attacker knowing a flow UUID could use the `retrieve vertices order` function to load and cache a private graph, enumerate vertex identifiers, and use the `build vertex` function to execute specific vertices and obtain results. This occurs because `build graph from db no cache` performs a primary-key lookup without an owner filter. This flaw could lead to the disclosure of private flow structures, configured values, and selected outputs, and could trigger side effects configured by the victim and build-history records. It does not expose variable-store credentials or allow modification of the stored flow. **Recommendations** Update Langflow to version 1.10.1. As a temporary mitigation, restrict access to the 'POST /api/v1/build/{flow id}/vertices' and 'POST /api/v1/build/{flow id}/vertices/{vertex id}' endpoints.