CVE 6.3 MEDIUM

Langflow – Missing Authorization on download_image Endpoint_CVE-2026-5022

6.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Description

The '/api/v1/files/images/{flow_id}/{file_name}' endpoint does not enforce any authentication or authorization checks, allowing any unauthenticated user to download images belonging to any flow by knowing (or guessing) the flow ID and file name.

Basic Information

ID CVE-2026-5022
Source tenable
Published Mar 27, 2026 at 14:34
Modified Mar 27, 2026 at 15:10

Affected Product

Vendor langflow-ai
Product langflow
Affected Versions langflow-ai langflow 0

CWE Classification

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.