CVE-2026-5022 identifies an improper authorization vulnerability (CWE-862) in an unspecified product, where the '/api/v1/files/images/{flow_id}/{file_name}' endpoint lacks authentication and authorization checks. This flaw permits unauthenticated attackers to download images associated with any flow by knowing or guessing the flow ID and file name, potentially leading to information disclosure. Rated with a CVSSv4 score of 6.3 (Medium), exploitation requires high attack complexity due to the need for specific knowledge or successful guessing, but can be performed remotely over the network without user interaction or privileges. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:langflow:langflow:-:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Langflow - Missing Authorization on download_image endpoint
Mar 27, 2026Langflow - Missing Authorization on download_image endpoint
Mar 27, 2026Langflow - Missing Authorization on download_image endpoint
Mar 27, 2026