{"id":"GHSA-9cc5-j3qq-69gv","title":"Duplicate Advisory: Unauthenticated Flow Execution via Webhook Authentication Bypass","summary":"Duplicate Advisory: Unauthenticated Flow Execution via Webhook Authentication Bypass","severity":"critical","cvss":9.8,"cwe":["CWE-306"],"vendor":"langflow","product":"langflow","ecosystem":"pip","affected":["langflow >= 1.7.0, <= 1.9.0"],"published":"2026-07-17","updated":"2026-10-05","sourceUpdated":"2026-10-05T22:31:17Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-9cc5-j3qq-69gv","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8505"},{"url":"https://www.ibm.com/support/pages/node/7278921"},{"url":"https://github.com/advisories/GHSA-9cc5-j3qq-69gv"}],"tags":["ghsa","pip"],"ingestedAt":"2026-10-05T22:35:24.746Z","slug":"GHSA-9cc5-j3qq-69gv","body":"## Overview\n\n## Duplicate Advisory\n\nThis advisory has been withdrawn because it is a duplicate of GHSA-cf6m-vc3m-7cgm. This link is maintained to preserve external references.\n\n## Original Description\nIBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses API key validation when the WEBHOOK_AUTH_ENABLE configuration is set to False (which is the default setting). This allows a remote attacker who knows a flow's UUID to execute it as if they were the owner, potentially leading to Remote Code Execution (RCE).\n\n## Affected packages\n\n- `langflow >= 1.7.0, <= 1.9.0`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}