/Vulnerability Library

Langflow - Broken Access Control

CVE-2026-21445
Verified

Description

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0.dev45, multiple critical API endpoints in Langflow are missing authentication controls. The issue allows any unauthenticated user to access sensitive user conversation data, transaction histories, and perform destructive operations including message deletion. This affects endpoints handling personal data and system operations that should require proper authorization.

Severity

Critical

CVSS Score

9.1

Exploit Probability

33%

Affected Product

langflow

Published Date

March 25, 2026

Template Author

dhiyaneshdk

CVE-2026-21445.yaml
9.1Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVE ID:
cve-2026-21445
CWE ID:
cwe-306

References

https://github.com/langflow-ai/langflow/security/advisories/GHSA-c5cp-vx83-jhqxhttps://nvd.nist.gov/vuln/detail/CVE-2026-21445

Remediation Steps

Update to version 1.7.0.dev45 or later.