


Perceptive Security
SOC/SIEM Consultancy

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions 1.0.0 through 1.8.1, the `/api/v1/files/images/{flow_id}/{file_name}`…
Published:
23 maart 2026 om 23:00:00
Alert date:
24 maart 2026 om 16:16:53
Source:
nvd.nist.gov
Web Technologies, Identity & Access
Langflow versions 1.0.0 through 1.8.1 contain an authentication bypass vulnerability in the image file serving endpoint. The /api/v1/files/images/{flow_id}/{file_name} endpoint serves image files without any authentication or ownership verification. In multi-tenant deployments, attackers can access any user's uploaded images by discovering or guessing flow IDs. UUIDs can be leaked through other API responses, making exploitation possible. The vulnerability allows unauthorized access to user images with HTTP 200 responses. Version 1.9.0 contains a patch that addresses this security issue.
Technical details
Mitigation steps:
Affected products:
Langflow
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-33484
https://github.com/langflow-ai/langflow/security/advisories/GHSA-7grx-3xcx-2xv5
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
