CVE-2026-105699
Received Received - Intake

Unauthorized File Access in Langflow AI Workflows

Vulnerability report for CVE-2026-105699, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.6.8 until 1.9.1, Langflow authenticated access to the project identifier in a project-scoped MCP connection but did not authorize the resource URI supplied to resources/read. read_resource forwarded the attacker-controlled URI to handle_read_resource, which parsed a flow_id and filename and called storage_service.get_file without verifying that the flow belonged to the authenticated user or current project. A user with access to any project-scoped MCP endpoint could therefore request another user's flow-backed file, while global handle_list_resources and handle_list_tools behavior could disclose flow and file identifiers that made targeting easier. The vulnerability disclosed uploaded documents, structured data, prompts, and other private flow artifacts across tenants but did not modify victim files or stored flows. This issue is fixed in version 1.9.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
langflow-ai langflow >= 1.6.8, <= 1.9.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Langflow is a tool for building AI-powered agents and workflows. This vulnerability allowed authenticated users with access to project-scoped MCP endpoints to read files belonging to other users by manipulating resource URIs. The issue occurred because the system did not properly verify ownership of flows or files before granting access.

Detection Guidance

This vulnerability involves unauthorized access to project files in Langflow versions 1.6.8 to 1.9.1. To detect it, check for unusual access patterns to resources/read endpoints, especially cross-project file requests. Review logs for requests to MCP endpoints with unexpected flow IDs or filenames. Verify if users accessed files outside their project scope.

Impact Analysis

This vulnerability could allow unauthorized users to access sensitive data such as uploaded documents, prompts, and other private flow artifacts across different tenants. It did not allow modification of files or stored flows but exposed confidential information.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, potentially violating GDPR, HIPAA, and other privacy regulations. Exposure of private flow artifacts may result in non-compliance with data protection requirements.

Mitigation Strategies

Upgrade Langflow to version 1.9.1 or later immediately to patch the vulnerability. Restrict access to project-scoped MCP endpoints to authorized users only. Review and audit recent access logs for suspicious activity. Ensure no unauthorized files were accessed and rotate any exposed credentials.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105699. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart