PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105698 langflow-ai CVE debrief

CVE-2026-105698 debrief based on the supplied source corpus. The CVE record was published on 2026-10-07T20:36:25.000Z and has not been modified since then. Langflow versions before 1.10.1 had two deprecated endpoints that did not check if the authenticated caller owned the flow referenced in the URL path, allowing any authenticated user to load another user's private flow graph, enumerate its vertex IDs, and build individual vertices. The issue is fixed in Langflow 1.10.1 (langflow-base 0.10.1) by [#13153](https://github.com/langflow-ai/langflow/pull/13153).

Vendor
langflow-ai
Product
langflow
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Langflow users and administrators should assess exposure and prioritize upgrading to version 1.10.1 or later. They should review affected versions, monitor for suspicious activity, and verify the remediation of exposed systems. Security teams should track exceptions, retest remediated assets, and ensure that evidence is documented.

Why it matters

CVE-2026-105698 allows authenticated users to access and execute vertices of other users' private flow graphs in Langflow versions before 1.10.1. Defenders should prioritize upgrading to version 1.10.1 or later and review affected versions.

  • Authenticated users could access private flow graphs of other users
  • Authenticated users could enumerate vertex IDs of other users' flow graphs
  • Authenticated users could build individual vertices of other users' flow graphs
  • Verification of affected versions and remediation priority is required

Technical summary

The Langflow application had two deprecated endpoints that did not check if the authenticated caller owned the flow referenced in the URL path, allowing any authenticated user to load another user's private flow graph, enumerate its vertex IDs, and build individual vertices. The endpoints are declared with `deprecated=True, include_in_schema=False`, so they do not appear in the OpenAPI docs, but they remained registered on the router. The issue is fixed in Langflow 1.10.1 (langflow-base 0.10.1) by [#13153](https://github.com/langflow-ai/langflow/pull/13153).

Defensive priority

Langflow users should prioritize upgrading to version 1.10.1 or later to address the vulnerability.

Recommended defensive actions

  • Upgrade Langflow to version 1.10.1 or later
  • Review and update affected versions
  • Monitor for suspicious activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and source item provide details on the vulnerability, including the affected versions and the fixed version. The Langflow UI no longer calls the deprecated endpoints (it uses `POST /api/v1/build/{flow_id}/flow`), so they are only reachable by direct HTTP requests. Any authenticated user who knows (or obtains) another user's `flow_id` could load that user's private flow graph, enumerate its vertex IDs, and build (execute) individual vertices of it, receiving the vertex results in the response.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105698 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105698

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105698 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105698

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Langflow : Cross-user flow access and vertex execution via deprecated /api/v1/build/{flow_id}/ve

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/PyPI/GHSA-gh98-4phw-6fmw.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/langflow-ai/langflow/security/advisories/GHSA-gh98-4phw-6fmw

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/langflow-ai/langflow/pull/13153

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/langflow-ai/langflow/commit/fb3d6ec90b1e4d52eaa40915a64b1f86b6542f55

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/langflow-ai/langflow

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/langflow-ai/langflow/releases/tag/v1.10.1

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.