IDOR/BOLA Vulnerability in Langflow Tool by Langflow AI
CVE-2026-33760

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
23 June 2026

What is CVE-2026-33760?

Langflow is a tool designed for creating and deploying AI-driven agents and workflows. In versions prior to 1.9.0, it featured an API endpoint that inadvertently allowed authenticated users to access and manipulate other users’ resources—such as messages, sessions, build artifacts, and logs—without proper ownership verification. This led to a risk where users could read, modify, or delete another user's data if they possessed the resource ID or flow_id. While there exists one endpoint that correctly enforces ownership checks, this inconsistency highlights a serious oversight in security practices. The vulnerability has been resolved in version 1.9.0, reinforcing the need for rigorous API security measures.

Affected Version(s)

langflow < 1.9.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.