---
id: CVE-2026-55423
aliases:
  - GHSA-7hw8-6q6r-4276
  - PYSEC-2026-222
title: 'Langflow: Logout button does not clear session'
summary: 'Langflow: Logout button does not clear session'
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
vendor: langflow
product: langflow
ecosystem: pip
affected:
  - langflow < 1.7.0
patched:
  - langflow 1.7.0
published: '2026-06-19'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T15:00:04.766539580Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-7hw8-6q6r-4276'
references:
  - url: >-
      https://github.com/langflow-ai/langflow/security/advisories/GHSA-7hw8-6q6r-4276
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55423'
  - url: 'https://github.com/langflow-ai/langflow/pull/10527'
  - url: 'https://github.com/langflow-ai/langflow/pull/10528'
  - url: 'https://github.com/langflow-ai/langflow'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/langflow/PYSEC-2026-222.yaml
  - url: 'https://github.com/advisories/GHSA-7hw8-6q6r-4276'
tags:
  - osv
  - pip
  - ghsa
epss: 0.00222
epssPercentile: 0.11368
cwe:
  - CWE-613
ingestedAt: '2026-06-22T13:35:24.304Z'
---

## Overview

### Summary
The logout button does not clear the session. The previous user stays logged in unless another user explicitly logs in.

### Details
Not in auto login mode. Hosted on localhost. `access_token_lf` remains present in both Local Storage and Cookies. `refresh_token_lf` remains present in Cookies.

**Root cause:** the `/logout` endpoint deleted the authentication cookies without matching the original `httponly`/`samesite`/`secure`/`domain` parameters, so the browser kept them; additionally the frontend did not clear the auth cookies on logout.

```
LANGFLOW_AUTO_LOGIN: "False"
LANGFLOW_SUPERUSER: <set>
LANGFLOW_SUPERUSER_PASSWORD: <set>
LANGFLOW_SECRET_KEY: <set>
LANGFLOW_NEW_USER_IS_ACTIVE: "False"
LANGFLOW_ENABLE_SUPERUSER_CLI: "False"
```

### PoC
Click Logout. Hit refresh to return to previous screen.

### Impact
Users on shared computers may falsely believe they have terminated their session.

### Patches
Fixed in **1.7.0** (PRs #10527 and #10528). The logout endpoint now deletes the auth cookies using the same parameters they were created with, and the frontend clears the auth cookies on logout. Upgrade to **1.7.0 or later**.

## Affected packages

- `langflow < 1.7.0`

## Remediation

Upgrade to a patched release:

- `langflow 1.7.0`
