Intel

AIKIDO-2026-350193

langflow is vulnerable to Insecure Direct Object Reference (IDOR)

Insecure Direct Object Reference (IDOR)GHSA-gh98-4phw-6fmw Published Today

54

Medium Risk

This Affects:

PYTHONlangflow
1.0.0 - 1.9.6
Fixed in 1.10.0
Are you affected? Scan for Free

TL;DR

POST /api/v1/build/{flow_id}/vertices and POST /api/v1/build/{flow_id}/vertices/{vertex_id} authenticate the caller and then load the flow by id with no owner check. A signed-in user who knows another user's flow id can list that flow's vertex ids and run individual vertices, and the response includes those vertex outputs. The fix loads the flow only for its owner or a public flow and returns 404 otherwise.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and signed-in users can call the deprecated build vertex endpoints.

Background info

langflow is vulnerable to Insecure Direct Object Reference (IDOR) in versions 1.0.0 - 1.9.6.

How to fix this

Upgrade the langflow library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform