PT-2026-66536 · Ibm · Langflow Oss

CVE-2026-10700

·

Published

2026-07-30

·

Updated

2026-08-04

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Langflow OSS versions 1.0.0 through 1.8.4
Description Broken access control issues in the file handling API allow unauthorized access to user files, breaking tenant isolation in multi-user deployments. The endpoint '/api/v1/files/images/{flow id}/{file name}' lacks authentication and authorization checks, enabling unauthenticated remote attackers to retrieve image files using a valid flow id and file name. Furthermore, the endpoint '/api/v1/files/download/{flow id}/{file name}' fails to validate resource ownership, allowing authenticated users to perform an Insecure Direct Object Reference (IDOR)—a vulnerability where an application provides direct access to objects based on user-supplied input—to access files belonging to other users via arbitrary identifiers. This may lead to the unauthorized disclosure of sensitive data from private flows.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10700

Affected Products

Langflow Oss