DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-105698: CVE-2026-105698: Missing Authorization in Deprecated Chat Vertices Endpoints in Langflow

CVE-2026-105698: Missing Authorization in Deprecated Chat Vertices Endpoints in Langflow

Vulnerability ID: CVE-2026-105698
CVSS Score: 5.4
Published: 2026-10-07

A missing authorization vulnerability in Langflow versions 1.0.0 through 1.10.0 allows authenticated users (and unauthenticated users in versions prior to 1.7.2) to access private workflow structures and execute graph components by targeting deprecated API endpoints.

TL;DR

Unauthenticated or low-privilege users can execute private flow vertices and read workflow configurations in Langflow versions prior to 1.10.1.


Technical Details

  • CWE ID: CWE-862, CWE-639
  • Attack Vector: Network (AV:N)
  • CVSS Score: 5.4 (Medium)
  • EPSS Score: 0.00177
  • Exploit Status: Proof-of-Concept
  • KEV Status: Not Listed

Affected Systems

  • Langflow
  • langflow-base
  • langflow: >= 1.0.0, < 1.10.1 (Fixed in: 1.10.1)
  • langflow-base: < 0.10.1 (Fixed in: 0.10.1)

Code Analysis

Commit: fb3d6ec

Implement pluggable Role-Based Access Control and strict ownership queries to prevent unauthorized vertex execution

Mitigation Strategies

  • Upgrade Langflow to version 1.10.1 or higher.
  • Upgrade langflow-base to version 0.10.1 or higher.
  • Implement reverse proxy rules to drop requests to deprecated vertices endpoints.
  • Configure WAF signatures to detect and block access to endpoints matching the deprecated route paths.

Remediation Steps:

  1. Identify all deployment instances of Langflow and verify current running versions.
  2. Execute pip update command: pip install --upgrade langflow langflow-base
  3. Verify the application version reports 1.10.1 (Langflow) and 0.10.1 (langflow-base) or newer.
  4. Deploy custom Nginx ingress or WAF configurations if patching windows are delayed.

References


Read the full report for CVE-2026-105698 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)