CVE-2026-34046: Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check
Vulnerability
IDOR in GET/PATCH/DELETE /api/v1/flow/{flowid}
The readflow helper in src/backend/base/langflow/api/v1/flows.py branched on the AUTOLOGIN setting to decide whether to filter by userid. When AUTOLOGIN was False (i.e., authentication was enabled), neither branch enforced an ownership check — the query returned any flow matching the given UUID regardless of who owned it.
This exposed any authenticated user to:
- Read any other user's flow, including embedded plaintext API keys - Modify the logic of another user's AI agents - Delete flows belonging to other users
The vulnerability was introduced by the conditional logic that was meant to accommodate public/example flows (those with userid = NULL) under auto-login mode, but inadvertently left the authenticated path without an ownership filter.
---
Fix (PR #8956)
The fix removes the AUTOLOGIN conditional entirely and unconditionally scopes the query to the requesting user:
diff - authsettings = settingsservice.authsettings - stmt = select(Flow).where(Flow.id == flowid) - if authsettings.AUTOLOGIN: - stmt = stmt.where( - (Flow.userid == userid) | (Flow.userid == None) # noqa: E711 - ) + stmt = select(Flow).where(Flow.id == flowid).where(Flow.userid == userid)
All three operations — read, update, and delete — route through readflow, so the single change covers the full attack surface. A cross-user isolation test (testreadflowsuserisolation) was added to prevent regression.
---
Acknowledgements
Langflow thanks the security researcher who responsibly disclosed this vulnerability:
- @chximn-dt
Other sources
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.5.1, the readflow helper in src/backend/base/langflow/api/v1/flows.py branched on the AUTOLOGIN setting to decide whether to filter by userid. When AUTOLOGIN was False (i.e., authentication was enabled), neither branch enforced an ownership check — the query returned any flow matching the given UUID regardless of who owned it. This allowed any authenticated user to read any other user's flow, including embedded plaintext API keys; modify the logic of another user's AI agents, and/or delete flows belonging to other users. The vulnerability was introduced by the conditional logic that was meant to accommodate public/example flows (those with userid = NULL) under auto-login mode, but inadvertently left the authenticated path without an ownership filter. The fix in version 1.5.1 removes the AUTOLOGIN conditional entirely and unconditionally scopes the query to the requesting user.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34046?
CVE-2026-34046 is classified as a critical vulnerability due to the potential for unauthorized access and data manipulation.
How do I fix CVE-2026-34046?
To fix CVE-2026-34046, update the langflow-base package to version 0.5.1 or the langflow package to version 1.5.1.
What type of vulnerability is CVE-2026-34046?
CVE-2026-34046 is an Insecure Direct Object Reference (IDOR) vulnerability affecting specific API endpoints.
Which versions are affected by CVE-2026-34046?
CVE-2026-34046 affects langflow-base versions up to 0.5.0 and langflow versions up to 1.5.0.
What are the potential impacts of CVE-2026-34046?
The impacts of CVE-2026-34046 may include unauthorized data access and modification through API endpoints.