Access Control Flaw in Langflow Affects AI Workflows by Langflow
CVE-2026-105699
7.1HIGH
What is CVE-2026-105699?
Langflow, a tool designed for building AI-powered agents and workflows, has a vulnerability in versions 1.6.8 through 1.9.1, affecting project-scoped MCP connections. The flaw allows authenticated users to access unauthorized resources by exploiting insufficient authorization checks on resource URIs. An attacker could potentially request flow-backed files from other users, compromising sensitive documents, structured data, and other private information across tenant projects without altering any files. This issue was resolved in version 1.9.1, which implements necessary authorization measures to prevent unauthorized access.
Affected Version(s)
langflow >= 1.6.8, <= 1.9.0
