{"schema_version":"1.9.0","id":"GHSA-gh98-4phw-6fmw","published":"2026-10-07T20:36:25Z","modified":"2026-10-07T20:45:05.457438477Z","aliases":["CVE-2026-105698"],"summary":"Langflow : Cross-user flow access and vertex execution via deprecated /api/v1/build/{flow_id}/vertices endpoints","details":"### Summary\n\nBefore **Langflow 1.10.1**, two deprecated but still-routed endpoints in the chat API did not check that the authenticated caller owns the flow referenced in the URL path:\n\n- `POST /api/v1/build/{flow_id}/vertices` (`retrieve_vertices_order`)\n- `POST /api/v1/build/{flow_id}/vertices/{vertex_id}` (`build_vertex`)\n\nAny authenticated user who knows (or obtains) another user's `flow_id` could load that user's private flow graph, enumerate its vertex IDs, and build (execute) individual vertices of it, receiving the vertex results in the response.\n\nBoth routes are declared with `deprecated=True, include_in_schema=False`, so they do not appear in the OpenAPI docs, but they remained registered on the router. The Langflow UI no longer calls them (it uses `POST /api/v1/build/{flow_id}/flow`), so they are only reachable by direct HTTP requests.\n\nThe issue is fixed in **Langflow 1.10.1** (`langflow-base` 0.10.1) by [#13153](https://github.com/langflow-ai/langflow/pull/13153).\n\n### Details\n\nIn affected versions, both handlers go straight to the graph loader:\n\n- `retrieve_vertices_order` (`src/backend/base/langflow/api/v1/chat.py`, lines 81-159 in 1.9.1) only required authentication via `dependencies=[Depends(get_current_active_user)]`. The user was never injected into the handler, and the flow was loaded with `build_graph_from_db(flow_id=flow_id, ...)`.\n- `build_vertex` (`chat.py`, lines 320-491 in 1.9.1) receives `current_user`, but only uses it for variable resolution (`user_id=str(current_user.id)`). It is never used to scope the flow lookup. The graph is taken from the chat-service cache keyed by `flow_id`, or rebuilt with `build_graph_from_db` on a cache miss.\n- `build_graph_from_db_no_cache` (`src/backend/base/langflow/api/utils/flow_utils.py`) does a bare primary-key lookup, `session.get(Flow, flow_id)`, with no owner filter.\n\nThe supported replacement, `POST /api/v1/build/{flow_id}/flow`, already restricted the lookup to the owner or a `PUBLIC` flow (added in #12305 for GHSA-qj98-rhf8-v93f). The deprecated siblings were not covered by that fix, nor by the `_read_flow` fix for GHSA-8c4j-f57c-35cf.\n\nAdditional side effects in affected versions:\n\n- `retrieve_vertices_order` stores the graph in the chat-service cache under the victim's `flow_id` (`chat_service.set_cache(str(flow_id), graph)`). When the request includes a `data` body, the cached graph is attacker-supplied.\n- `build_vertex` schedules `log_vertex_build` for the victim's `flow_id`, so attacker-triggered builds are recorded in the victim flow's vertex build history.\n\nNote on older versions: up to and including **1.7.1**, these two routes had no authentication dependency at all. Authentication was added in 1.7.2 by #10977, but no ownership check was added. This advisory covers the missing ownership check, which is present in every release from 1.0.0 (when the routes were introduced) through 1.10.0.\n\n### Attack scenario\n\n1. The attacker authenticates as any valid user.\n2. The attacker obtains a victim `flow_id` (shared URLs, exported flow files, logs, screenshots, etc.).\n3. `POST /api/v1/build/{victim_flow_id}/vertices` returns **200 OK** with `{\"ids\": [...], \"run_id\": \"...\", \"vertices_to_run\": [...]}` listing the victim flow's vertex IDs (component type plus suffix, e.g. `ChatInput-abc12`).\n4. The attacker calls `POST /api/v1/build/{victim_flow_id}/vertices/{vertex_id}` for a returned ID. The victim's graph is loaded and the vertex is built. Its results, outputs and artifacts are returned to the attacker.\n\n### Impact\n\n- **Confidentiality (Low):** Discloses the structure of private flows (vertex IDs and component types) and the outputs of vertices the attacker chooses to build. That includes values hardcoded in node configuration, such as prompt text or fixed inputs.\n  - Global variables and credentials in the variable store are **not** exposed, because variable resolution uses the caller's `user_id`.\n  - The victim's stored flow definition is not returned wholesale.\n- **Integrity (Low):** The attacker can trigger execution of the victim's nodes, including any side effects baked into their configuration (fixed endpoints, webhooks, hardcoded API keys). Build records are written under the victim's `flow_id`. The attacker cannot modify the stored flow.\n- **Availability:** None.\n\nThe attacker must be authenticated and must know the target flow UUID. Flow UUIDs are random v4 values, so blind enumeration is not practical.\n\n### Proof of concept\n\nObserved on `langflow==1.9.1` using the project's test client and in-memory SQLite fixtures (see the attached `poc.zip`):\n\n| Request | Expected (hardened) | Observed on 1.9.1 |\n|---|---|---|\n| Attacker → `POST /api/v1/build/{victim_flow_id}/vertices` | `404 Not Found` | `200 OK` with vertex order payload |\n| Attacker → `POST /api/v1/build/{victim_flow_id}/vertices/<bogus-id>` | `404 Not Found` | `500` `{\"detail\":\"Vertex <id> not found\"}`: the victim graph was loaded before the vertex lookup failed |\n| Owner (control) → same endpoints | non-404 | non-404 |\n\nOn 1.10.1 and later, the attacker requests return `404 Not Found`. This is covered by regression tests in `src/backend/tests/unit/test_endpoints.py`:\n\n- `test_get_vertices_returns_404_for_other_users_private_flow`\n- `test_get_vertices_with_supplied_data_returns_404_for_other_users_private_flow`\n- `test_build_vertex_returns_404_for_other_users_private_flow`\n\n### Patches\n\nFixed in **Langflow 1.10.1** (`langflow-base` 0.10.1) by [#13153](https://github.com/langflow-ai/langflow/pull/13153) (merge commit `fb3d6ec90b`). Both handlers now:\n\n1. inject `current_user` (for `retrieve_vertices_order`, this replaces the dependencies-only declaration),\n2. load the flow with an owner-scoped query and return `404` when it is not found, so a flow you don't own looks the same as a missing flow, and\n3. call `ensure_flow_permission(current_user, FlowAction.EXECUTE, ...)` before building or caching any graph.\n\n```python\n# retrieve_vertices_order / build_vertex (1.10.1)\nstmt = (\n    select(Flow)\n    .where(Flow.id == flow_id)\n    .where((Flow.user_id == current_user.id) | (Flow.access_type == AccessTypeEnum.PUBLIC))\n)\nflow = (await session.exec(stmt)).first()\nif not flow:\n    raise HTTPException(status_code=404, detail=f\"Flow with id {flow_id} not found\")\nawait ensure_flow_permission(\n    current_user,\n    FlowAction.EXECUTE,\n    flow_id=flow_id,\n    flow_user_id=flow.user_id,\n    workspace_id=flow.workspace_id,\n    folder_id=flow.folder_id,\n)\n```\n\nRelated hardening in later releases:\n\n- [#14342](https://github.com/langflow-ai/langflow/pull/14342) (1.11.2) applies the same guard to the sibling `GET /api/v1/build/{flow_id}/{vertex_id}/stream` route.\n- [#14497](https://github.com/langflow-ai/langflow/pull/14497) (1.12.0) makes all three deprecated vertex routes owner-only, dropping the `PUBLIC` exception, because their graph cache is keyed by flow UUID rather than by the executing user.\n\nUsers should upgrade to **1.10.1 or later**. The latest release is recommended.\n\n### Workarounds\n\nIf upgrading is not immediately possible, block `POST /api/v1/build/*/vertices` and `POST /api/v1/build/*/vertices/*` (and `GET /api/v1/build/*/*/stream`) at a reverse proxy. The Langflow UI does not use these routes.","affected":[{"package":{"name":"langflow","ecosystem":"PyPI","purl":"pkg:pypi/langflow"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0"},{"fixed":"1.10.1"}]}],"versions":["1.0.0","1.0.1","1.0.10","1.0.11","1.0.12","1.0.13","1.0.14","1.0.15","1.0.16","1.0.17","1.0.18","1.0.19","1.0.19.post1","1.0.19.post2","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.0.8","1.0.9","1.1.0","1.1.1","1.1.2","1.1.3","1.1.4","1.1.4.post1","1.10.0","1.10.0rc0","1.10.1rc0","1.10.1rc3","1.2.0","1.3.0","1.3.1","1.3.2","1.3.3","1.3.4","1.4.0","1.4.1","1.4.2","1.4.3","1.5.0","1.5.0.post1","1.5.0.post2","1.5.1","1.6.0","1.6.1","1.6.2","1.6.3","1.6.4","1.6.5","1.6.6","1.6.7","1.6.8","1.6.9","1.7.0","1.7.1","1.7.2","1.7.3","1.8.0","1.8.0rc0","1.8.0rc1","1.8.0rc2","1.8.0rc3","1.8.0rc4","1.8.0rc5","1.8.0rc6","1.8.1","1.8.2","1.8.3","1.8.3rc0","1.8.4","1.9.0","1.9.1","1.9.2","1.9.3","1.9.3rc0","1.9.4","1.9.5","1.9.6","1.9.6rc0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-gh98-4phw-6fmw/GHSA-gh98-4phw-6fmw.json"}},{"package":{"name":"langflow-base","ecosystem":"PyPI","purl":"pkg:pypi/langflow-base"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.10.1"}]}],"versions":["0.0.13","0.0.14","0.0.15","0.0.16","0.0.17","0.0.18","0.0.19","0.0.20","0.0.21","0.0.22","0.0.23","0.0.24","0.0.25","0.0.26","0.0.27","0.0.28","0.0.29","0.0.30","0.0.31","0.0.32","0.0.33","0.0.34","0.0.35","0.0.36","0.0.37","0.0.38","0.0.39","0.0.40","0.0.41","0.0.42","0.0.43","0.0.44","0.0.45","0.0.46","0.0.47","0.0.48","0.0.49","0.0.50","0.0.51","0.0.52","0.0.53","0.0.54","0.0.55","0.0.56","0.0.57","0.0.58","0.0.59","0.0.60","0.0.61","0.0.62","0.0.63","0.0.64","0.0.66","0.0.67","0.0.68","0.0.69","0.0.70","0.0.71","0.0.72","0.0.73","0.0.74","0.0.75","0.0.76","0.0.77","0.0.78","0.0.79","0.0.80","0.0.81","0.0.82","0.0.83","0.0.84","0.0.85","0.0.86","0.0.87","0.0.88","0.0.89","0.0.90","0.0.91","0.0.92","0.0.93","0.0.94","0.0.95","0.0.96","0.0.97","0.0.98","0.0.99","0.1.0","0.1.1","0.1.2","0.1.3","0.1.4","0.1.4.post1","0.10.0","0.10.0rc0","0.10.1rc0","0.10.1rc3","0.2.0","0.3.0","0.3.1","0.3.2","0.3.3","0.3.4","0.4.0","0.4.1","0.4.2","0.4.3","0.5.0","0.5.0.post1","0.5.0.post2","0.5.1","0.6.0","0.6.1","0.6.2","0.6.3","0.6.4","0.6.5","0.6.6","0.6.7","0.6.8","0.6.9","0.7.0","0.7.1","0.7.2","0.7.3","0.8.0","0.8.0rc0","0.8.0rc1","0.8.0rc2","0.8.0rc3","0.8.0rc4","0.8.0rc5","0.8.0rc6","0.8.1","0.8.2","0.8.3","0.8.3rc0","0.8.4","0.9.0","0.9.1","0.9.2","0.9.3","0.9.3rc0","0.9.4","0.9.5","0.9.6","0.9.6rc0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-gh98-4phw-6fmw/GHSA-gh98-4phw-6fmw.json"}}],"references":[{"type":"WEB","url":"https://github.com/langflow-ai/langflow/security/advisories/GHSA-gh98-4phw-6fmw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105698"},{"type":"WEB","url":"https://github.com/langflow-ai/langflow/pull/13153"},{"type":"WEB","url":"https://github.com/langflow-ai/langflow/commit/fb3d6ec90b1e4d52eaa40915a64b1f86b6542f55"},{"type":"PACKAGE","url":"https://github.com/langflow-ai/langflow"},{"type":"WEB","url":"https://github.com/langflow-ai/langflow/releases/tag/v1.10.1"}],"database_specific":{"cwe_ids":["CWE-639","CWE-862"],"github_reviewed":true,"github_reviewed_at":"2026-10-07T20:36:25Z","nvd_published_at":"2026-10-05T21:16:35Z","severity":"MODERATE"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"}]}