Answer in brief
CVE-2026-105698 records a Medium severity (CVSS 5.4) vulnerability in Langflow: Cross-user flow access and vertex execution via deprecated /api/v1/build/{flow_id}/vertices endpoints. The current sources do not mark it as known exploited. The current feed maps langflow-ai/langflow (generic), langflow-ai/langflow-base (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.4. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps langflow-ai/langflow (generic), langflow-ai/langflow-base (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| langflow-ai/langflowgeneric | >=1.0.0 <1.10.1 | 1.10.1 |
| langflow-ai/langflow-basegeneric | <0.10.1 | 0.10.1 |
Published upstream
Oct 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 5, 2026
Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.0.0 until 1.10.1, Langflow did not verify flow ownership in the deprecated POST /api/v1/build/{flow_id}/vertices and POST /api/v1/build/{flow_id}/vertices/{vertex_id} handlers. Through version 1.7.1, an unauthenticated caller who knew another user's flow UUID could reach these handlers; from version 1.7.2 through 1.10.0, callers had to authenticate but needed no elevated privileges. Such a caller could cause retrieve_vertices_order to load and cache the private graph, enumerate its vertex identifiers, and use build_vertex to execute selected vertices and receive their results. build_graph_from_db_no_cache performed a primary-key lookup without an owner filter. This could disclose private flow structure, configured values, and selected outputs and could trigger victim-configured side effects and build-history records, although it did not expose the victim's variable-store credentials or permit modification of the stored flow. This issue is fixed in Langflow 1.10.1 and langflow-base 0.10.1.
Quoted source text, attributed separately from HOL analysis.