CVE-2026-34046High▾ TwilightLangflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.5%
GET/PATCH/DELETE /api/v1/flow/{flow_id}The _read_flow helper in src/backend/base/langflow/api/v1/flows.py branched on the AUTO_LOGIN setting to decide whether to filter by user_id. When AUTO_LOGIN was False (i.e., authentication was enabled), neither branch enforced an ownership check — the query returned any flow matching the given UUID regardless of who owned it.
This exposed any authenticated user to:
The vulnerability was introduced by the conditional logic that was meant to accommodate public/example flows (those with user_id = NULL) under auto-login mode, but inadvertently left the authenticated path without an ownership filter.
The fix removes the AUTO_LOGIN conditional entirely and unconditionally scopes the query to the requesting user:
- auth_settings = settings_service.auth_settings
- stmt = select(Flow).where(Flow.id == flow_id)
- if auth_settings.AUTO_LOGIN:
- stmt = stmt.where(
- (Flow.user_id == user_id) | (Flow.user_id == None) # noqa: E711
- )
+ stmt = select(Flow).where(Flow.id == flow_id).where(Flow.user_id == user_id)
All three operations — read, update, and delete — route through _read_flow, so the single change covers the full attack surface. A cross-user isolation test (test_read_flows_user_isolation) was added to prevent regression.
Langflow thanks the security researcher who responsibly disclosed this vulnerability:
langflow < 1.5.1langflow-base < 0.5.1Upgrade to a patched release:
langflow 1.5.1langflow-base 0.5.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-6599Medium· 6.3Langflow vulnerable to injection
CVE-2026-6598Medium· 4.3Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint
CVE-2026-6597Low· 2.7Langflow has an Information Leak through Incomplete API Key Redaction
CVE-2026-0770HighLangflow affected by Remote Code Execution via validate_code() exec()
CVE-2024-48061Critical· 9.8Langflow vulnerable to remote code execution
CVE-2025-68477High· 7.7Langflow vulnerable to Server-Side Request Forgery