Vulnerability  ·  2026-06-24

Langflow Monitor Router IDOR — 7 Unauthenticated Endpoints Expose All Users' Session Data

VulnerabilityHigh impactGlobalCVE-2026-33760
Prior to Langflow 1.9.0, the /api/v1/monitor router exposes 7 endpoints that perform read, write, and delete operations on messages, sessions, build artifacts, and LLM transaction logs without verifying that the caller owns the target resource. CVSS 8.8 High, published 2026-06-23.
An authenticated attacker can read all LLM transaction logs from any user (revealing prompts, completions, and any sensitive data processed by AI flows), delete other users' sessions and build artifacts, and manipulate message history — undermining audit trails, compliance logging, and data privacy for the entire multi-user deployment.
Authenticated requests to /api/v1/monitor/* endpoints specifying victim user IDs or resource IDs; no ownership verification performed
Langflow < 1.9.0
Upgrade to Langflow 1.9.0. Advisory: https://github.com/langflow-ai/langflow/security/advisories/GHSA-9c59-2mvc-vfr8
Sources
NVD CVE-2026-33760GitHub Advisory GHSA-9c59-2mvc-vfr8
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →