criticalCVSS 9.8Vulnerability

CVE-2026-8505

### Summary A vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses API key validation when the `WEBHOOK_AUTH_ENABLE` configuration is set to `False`. This allows a remote attacker who knows a flow's UUID to execute it as if they were the owner, potentially leading to Remote Code Execution (RCE) or Denial of Service (DoS). ### Details The `WEBHOOK_AUTH_ENABLE` setting was introduced in v1.7.0 (#9139) with a default of `False`. The root cause is in the webhook authentication path, `AuthService.get_webhook_user` (`src/backend/base/langflow/services/auth/service.py`; the thin wrapper in `src/backend/base/langflow/services/auth/utils.py` just delegates to it): ```python async def get_webhook_user(self, flow_id: str, request: Request) -> UserRead: settings_service = self.settings ... # VULNERABILITY: If this setting is False (default in <= 1.9.0), it returns # the flow owner WITHOUT checking the API Key in the request. if not settings_service.auth_settings.WEBHOOK_AUTH_ENABLE: try: flow_owner = await get_user_by_flow_id_or_endpoint_name(flow_id) return flow_owner ``` By default (v1.7.0 through v1.9.0), Langflow treats `WEBHOOK_AUTH_ENABLE` as `False`, meaning all webhook endpoints are public. This relies exclusively on the secrecy of the `flow_id` (UUID), which is an insecure practice (Security by Obscurity). A related report, GHSA-6g4m-v5q2-475v, demonstrated a concrete RCE chain through this same bypass using the `PythonCodeStructuredTool` component (`exec()` on flow-authored Python code). That report is a duplicate of this root cause and has been closed in favor of this advisory; credit for that PoC has been added here. ### PoC 1. Identify a valid `flow_id` for a flow that performs a sensitive action (e.g., sending an email, writing to a database, or executing a Python script). 2. Execute a POST request to the w

Properties

severity
critical
summary
Langflow: Unauthenticated Flow Execution via Webhook Authentication Bypass
epss_score
0.01041
cvss_score
9.8
retrieved_at
2026-10-05T22:59:58+00:00
ghsa_published
2026-10-05T22:31:22Z
source_url
https://github.com/advisories/GHSA-cf6m-vc3m-7cgm
ghsa_updated
2026-10-05T22:31:23Z
ghsa_id
GHSA-cf6m-vc3m-7cgm
last_source
FIRST EPSS
cve_id
CVE-2026-8505
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
signal_observed_at
2026-10-05T22:52:21+00:00
is_ghsa_only
false
epss_percentile
0.62804

Related Entities (5)

ENRICHED_BY (1)

→[Source]FIRST EPSS

VULNERABLE_TO (1)

←[Software]pip/langflow

AFFECTS (1)

→[Software]pip/langflow

HAS_WEAKNESS (1)

→[Weakness]Missing Authentication for Critical Function

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-8505 (CVSS 9.8) — Ninja Signal Threat Intelligence | Ninja Signal