IDOR/BOLA Vulnerability in Langflow Tool by Langflow AI
CVE-2026-33760
8.8HIGH
What is CVE-2026-33760?
Langflow is a tool designed for creating and deploying AI-driven agents and workflows. In versions prior to 1.9.0, it featured an API endpoint that inadvertently allowed authenticated users to access and manipulate other users’ resources—such as messages, sessions, build artifacts, and logs—without proper ownership verification. This led to a risk where users could read, modify, or delete another user's data if they possessed the resource ID or flow_id. While there exists one endpoint that correctly enforces ownership checks, this inconsistency highlights a serious oversight in security practices. The vulnerability has been resolved in version 1.9.0, reinforcing the need for rigorous API security measures.
Affected Version(s)
langflow < 1.9.0
