Access Control Flaw in Langflow Affects AI Workflows by Langflow
CVE-2026-105699

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105699?

Langflow, a tool designed for building AI-powered agents and workflows, has a vulnerability in versions 1.6.8 through 1.9.1, affecting project-scoped MCP connections. The flaw allows authenticated users to access unauthorized resources by exploiting insufficient authorization checks on resource URIs. An attacker could potentially request flow-backed files from other users, compromising sensitive documents, structured data, and other private information across tenant projects without altering any files. This issue was resolved in version 1.9.1, which implements necessary authorization measures to prevent unauthorized access.

Affected Version(s)

langflow >= 1.6.8, <= 1.9.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.