CVE 8.8 HIGH

Langflow Missing Authentication on Critical API Endpoints_CVE-2026-21445

8.8 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P

Description

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0.dev45, multiple critical API endpoints in Langflow are missing authentication controls. The issue allows any unauthenticated user to access sensitive user conversation data, transaction histories, and perform destructive operations including message deletion. This affects endpoints handling personal data and system operations that should require proper authorization. Version 1.7.0.dev45 contains a patch.

AI Analysis

Missing authentication controls on critical API endpoints allow unauthenticated users to access sensitive data and perform destructive operations.

Basic Information

ID CVE-2026-21445
Source GitHub_M
Published Jan 2, 2026 at 19:11
Modified Jan 2, 2026 at 19:13

Affected Product

Vendor langflow-ai
Product langflow
Version < 1.7.0.dev45
Affected Versions langflow-ai langflow < 1.7.0.dev45

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor langflow-ai
Product Langflow
Version < 1.7.0.dev45

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.