CVE-2026-33053 is an Insecure Direct Object Reference (IDOR) vulnerability (CWE-639) affecting Langflow versions prior to 1.9.0. This flaw allows an authenticated, low-privileged attacker to delete any user's API key by specifying its ID, as the system fails to verify ownership during the deletion process. Rated 8.8 HIGH on the CVSS scale, this network-exploitable vulnerability has high impacts on confidentiality, integrity, and availability, as it can lead to unauthorized access or service disruption. While no public exploit code or active exploitation has been observed, and it is not listed in the CISA KEV catalog, the vulnerability has received minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.9.0CPE matchmatch criteria | cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.