Executive brief
IBM Langflow OSS is an open-source workflow automation platform used to build and execute AI-powered applications. Multiple authentication and authorization flaws allow unauthenticated or low-privileged attackers to execute arbitrary workflows, read sensitive files and configuration data, and access other users' private flows and chat history. This could enable attackers to steal API keys, model credentials, and user data, or manipulate workflow execution.
Technical details
Langflow OSS versions 1.0.0 through 1.11.1 contain multiple authentication and authorization bypass vulnerabilities. The MCP project authentication function fails to require API keys for auth_type=none mode, allowing unauthenticated callers to be resolved as the system superuser on certain transports. The public flow-build endpoint accepts an unvalidated files parameter that bypasses path containment checks, enabling arbitrary file reads. Deprecated API endpoints lack proper object-level ownership validation, permitting authenticated users to execute other tenants' private flows. Additionally, the flow metadata endpoint exposes user identifiers that can be reused to collide with other users' session namespaces, and the model instantiation path constructs provider SDK clients with tenant-controlled URLs that bypass SSRF protections. An attacker can achieve remote code execution, sensitive information disclosure, and lateral access across multi-tenant deployments. IBM recommends upgrading to version 1.11.2 or later.
Affected products
- IBM Langflow OSS 1.0.0 through 1.11.1
Timeline
- 2026-08-21: disclosed
- 2026-08-28: other: NVD published