CVE-2026-21445High▾ MidnightPoC availableLangflow Missing Authentication on Critical API Endpoints
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 41.3 · likelihood 6.7 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
21%
21% → 35%
1 GitHub repo · Nuclei ×1
Multiple critical API endpoints in Langflow are missing authentication controls, allowing any unauthenticated user to access sensitive user conversation data, transaction histories, and perform destructive operations including message deletion. This affects endpoints handling personal data and system operations that should require proper authorization.
The vulnerability exists in three API endpoints within src/backend/base/langflow/api/v1/monitor.py that are missing the required dependencies=[Depends(get_current_active_user)] authentication dependency:
Affected Endpoints:
GET /api/v1/monitor/messages (Line 61)
@router.get("/messages") # ❌ Missing authentication
async def get_messages(
session: DbSession,
flow_id: Annotated[UUID | None, Query()] = None,
session_id: Annotated[str | None, Query()] = None,
# ... other parameters
) -> list[MessageResponse]:
GET /api/v1/monitor/transactions (Line 183)
@router.get("/transactions") # ❌ Missing authentication
async def get_transactions(
flow_id: Annotated[UUID, Query()],
session: DbSession,
params: Annotated[Params | None, Depends(custom_params)],
) -> Page[TransactionTable]:
DELETE /api/v1/monitor/messages/session/{session_id} (Line 165)
@router.delete("/messages/session/{session_id}", status_code=204) # ❌ Missing authentication
async def delete_messages_session(
session_id: str,
session: DbSession,
):
Inconsistency Evidence: Other endpoints in the same file properly implement authentication:
@router.get("/messages/sessions", dependencies=[Depends(get_current_active_user)]) # ✅ Properly secured
@router.delete("/messages", status_code=204, dependencies=[Depends(get_current_active_user)]) # ✅ Properly secured
Complete reproduction steps to demonstrate the vulnerability:
Prerequisites:
Reproduction Commands:
# 1. Access all user conversations without authentication
curl http://localhost:7860/api/v1/monitor/messages
# 2. Access transaction history without authentication
curl "http://localhost:7860/api/v1/monitor/transactions?flow_id=00000000-0000-0000-0000-000000000000"
# 3. Delete user messages by session without authentication
curl -X DELETE http://localhost:7860/api/v1/monitor/messages/session/00000000-0000-0000-0000-000000000000
Expected vs Actual Behavior:
401 UnauthorizedVulnerability Type: Broken Authentication and Authorization (OWASP Top 10 - A01:2021)
Severity: High
Who is Impacted:
Specific Impacts:
Attack Scenarios:
Recommended Fix: Add authentication dependencies to all affected endpoints:
@router.get("/messages", dependencies=[Depends(get_current_active_user)])
@router.get("/transactions", dependencies=[Depends(get_current_active_user)])
@router.delete("/messages/session/{session_id}", dependencies=[Depends(get_current_active_user)])
Environment:
get_current_active_userlangflow-base < 0.7.1langflow < 1.7.1Upgrade to a patched release:
langflow-base 0.7.1langflow 1.7.1Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.