Intel

AIKIDO-2026-324694

langflow is vulnerable to Insecure Direct Object Reference (IDOR)

Insecure Direct Object Reference (IDOR)GHSA-4hmc-cfm3-w43c Published Today

71

High Risk

This Affects:

PYTHONlangflow
1.6.0 - 1.9.0
Fixed in 1.9.1
Are you affected? Scan for Free

TL;DR

Project MCP checks the caller against the project id in the connection URL, then handle_read_resource() reads the flow id and filename taken from the resource URI with no ownership check. A signed-in user can connect to their own project and read a file stored on another user's flow. The fix resolves that flow for the current user and project before it reads storage.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and signed-in users can open a project MCP endpoint.

Background info

langflow is vulnerable to Insecure Direct Object Reference (IDOR) in versions 1.6.0 - 1.9.0.

How to fix this

Upgrade the langflow library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform