PT-2026-106234 · Langflow · Langflow
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Langflow versions 1.6.8 through 1.9.0
Description
Langflow fails to properly authorize the resource URI provided to the
resources/read endpoint. The read resource function forwards the attacker-controlled URI to handle read resource, which parses a flow id and filename to call storage service.get file() without verifying if the flow belongs to the authenticated user or the current project. Consequently, a user with access to any project-scoped MCP endpoint can request files from another user's flow. Additionally, the handle list resources and handle list tools functions may disclose flow and file identifiers, facilitating targeted attacks. This issue allows the disclosure of uploaded documents, structured data, prompts, and other private flow artifacts across tenants, although it does not allow the modification of files or flows.Recommendations
Update to version 1.9.1.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Langflow