CVE-2026-34046 impacts Langflow versions prior to 1.5.1, where a missing ownership check in the `_read_flow` helper allowed authenticated users to read, modify, or delete any other user's flows. This vulnerability could expose sensitive data, such as embedded plaintext API keys, and enable unauthorized alteration or deletion of AI agent logic. Rated with a CVSSv4 score of 8.7 (High), it presents a network attack vector with low complexity, requiring only low privileges for exploitation, leading to high confidentiality, integrity, and availability impacts. Currently, there is no evidence of active exploitation, and no public exploit code is available in common repositories. Community discussion and media coverage for this CVE remain minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.0CPE matchmatch criteria | cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:langflow:langflow:1.5.0:dev0:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:langflow:langflow:1.5.0:dev1:*:*:*:*:*:* | ||
< 0.5.1CPE matchmatch criteria | cpe:2.3:a:langflow:langflow-base:*:*:*:*:*:python:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.