CYBER CODE RED

Get real-time updates on Telegram

P4Verified

Langflow: Unauthenticated Flow Execution via Webhook Authentication Bypass

CVE-2026-8505 affects langflow. CVSS base score 9.8 (GitHub Advisory Database). EPSS 0.01041 (percentile 0.62796), scored 2026-10-04. Affected range: >= 1.7.0, <= 1.9.0. Fixed version: 1.9.1.

Affected technology

langflow · >= 1.7.0, <= 1.9.0
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (GitHub Advisory Database, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

Unauthenticated users can trigger the execution of any flow. GitHub Advisory Database’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high.

Published

CVE
CVE-2026-8505
Product
langflow
CCR priority
39.5 /100 (P4)
CVSS
9.8 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H · GitHub Advisory Database
EPSS
0.01041 · percentile 0.62796 · 2026-10-04
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-8505.html