Executive brief
IBM Langflow OSS is an open-source platform for building and executing AI workflows using API keys for programmatic access. A vulnerability allows attackers with valid credentials to continue executing flows and accessing sensitive information even after their user account has been deactivated by an administrator, because API keys are not invalidated when accounts are disabled. This could enable former employees or compromised accounts to maintain unauthorized access to critical workflows and data.
Technical details
The vulnerability is an insufficient session expiration issue (CWE-613) in Langflow OSS 1.0.0 through 1.11.5. The database API-key validator does not verify whether the owning user account is active before granting authentication; API keys issued to users remain valid after their accounts are deactivated by an administrator. Additionally, the MCP (Model Context Protocol) HTTP API credential resolvers do not apply the same AUTO_LOGIN API-key guard enforced on standard authenticated endpoints, allowing unauthenticated requests to MCP endpoints to be resolved to the superuser in default configurations. An authenticated attacker with a valid API key can exploit this to execute flows and retrieve sensitive information. The attack requires network access and valid credentials but no user interaction. IBM recommends upgrading to version 1.11.6 or later.
Affected products
- IBM Langflow OSS 1.0.0 through 1.11.5
Timeline
- 2026-09-08: disclosed
- 2026-09-10: advisory