Описание
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. This vulnerability is fixed in 1.9.1.
Ссылки
- Patch
- Issue TrackingPatch
- ExploitMitigationVendor Advisory
- ExploitMitigationVendor Advisory
- Third Party Advisory
- US Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 1.9.1 (исключая)
cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*
EPSS
Процентиль: 57%
0.00887
Низкий
8.4 High
CVSS3
Дефекты
CWE-639
Связанные уязвимости
CVSS3: 8.4
github
3 месяца назад
Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
CVSS3: 8.4
fstec
3 месяца назад
Уязвимость функции get_flow_by_id_or_endpoint_name инструмента для создания и развёртывания агентов и рабочих процессов Langflow, позволяющая нарушителю обойти существующие ограничения безопасности
EPSS
Процентиль: 57%
0.00887
Низкий
8.4 High
CVSS3
Дефекты
CWE-639