top of page
perceptive_background_267k.jpg

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions 1.0.0 through 1.8.1, the `/api/v1/files/images/{flow_id}/{file_name}`…

Published:

23 maart 2026 om 23:00:00

Alert date:

24 maart 2026 om 16:16:53

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

Langflow versions 1.0.0 through 1.8.1 contain an authentication bypass vulnerability in the image file serving endpoint. The /api/v1/files/images/{flow_id}/{file_name} endpoint serves image files without any authentication or ownership verification. In multi-tenant deployments, attackers can access any user's uploaded images by discovering or guessing flow IDs. UUIDs can be leaked through other API responses, making exploitation possible. The vulnerability allows unauthorized access to user images with HTTP 200 responses. Version 1.9.0 contains a patch that addresses this security issue.

Technical details

Mitigation steps:

Affected products:

Langflow

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page