PatchSiren cyber security CVE debrief
CVE-2026-105698 langflow-ai CVE debrief
CVE-2026-105698 debrief based on the supplied source corpus. The CVE record was published on 2026-10-07T20:36:25.000Z and has not been modified since then. Langflow versions before 1.10.1 had two deprecated endpoints that did not check if the authenticated caller owned the flow referenced in the URL path, allowing any authenticated user to load another user's private flow graph, enumerate its vertex IDs, and build individual vertices. The issue is fixed in Langflow 1.10.1 (langflow-base 0.10.1) by [#13153](https://github.com/langflow-ai/langflow/pull/13153).
- Vendor
- langflow-ai
- Product
- langflow
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Langflow users and administrators should assess exposure and prioritize upgrading to version 1.10.1 or later. They should review affected versions, monitor for suspicious activity, and verify the remediation of exposed systems. Security teams should track exceptions, retest remediated assets, and ensure that evidence is documented.
Why it matters
CVE-2026-105698 allows authenticated users to access and execute vertices of other users' private flow graphs in Langflow versions before 1.10.1. Defenders should prioritize upgrading to version 1.10.1 or later and review affected versions.
- Authenticated users could access private flow graphs of other users
- Authenticated users could enumerate vertex IDs of other users' flow graphs
- Authenticated users could build individual vertices of other users' flow graphs
- Verification of affected versions and remediation priority is required
Technical summary
The Langflow application had two deprecated endpoints that did not check if the authenticated caller owned the flow referenced in the URL path, allowing any authenticated user to load another user's private flow graph, enumerate its vertex IDs, and build individual vertices. The endpoints are declared with `deprecated=True, include_in_schema=False`, so they do not appear in the OpenAPI docs, but they remained registered on the router. The issue is fixed in Langflow 1.10.1 (langflow-base 0.10.1) by [#13153](https://github.com/langflow-ai/langflow/pull/13153).
Defensive priority
Langflow users should prioritize upgrading to version 1.10.1 or later to address the vulnerability.
Recommended defensive actions
- Upgrade Langflow to version 1.10.1 or later
- Review and update affected versions
- Monitor for suspicious activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details on the vulnerability, including the affected versions and the fixed version. The Langflow UI no longer calls the deprecated endpoints (it uses `POST /api/v1/build/{flow_id}/flow`), so they are only reachable by direct HTTP requests. Any authenticated user who knows (or obtains) another user's `flow_id` could load that user's private flow graph, enumerate its vertex IDs, and build (execute) individual vertices of it, receiving the vertex results in the response.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105698 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105698
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105698 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105698
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Langflow : Cross-user flow access and vertex execution via deprecated /api/v1/build/{flow_id}/ve
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/PyPI/GHSA-gh98-4phw-6fmw.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/langflow-ai/langflow/security/advisories/GHSA-gh98-4phw-6fmw
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/langflow-ai/langflow/pull/13153
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/langflow-ai/langflow/commit/fb3d6ec90b1e4d52eaa40915a64b1f86b6542f55
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/langflow-ai/langflow
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/langflow-ai/langflow/releases/tag/v1.10.1
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.