The '/api/v1/files/images/{flow_id}/{file_name}' endpoint does not enforce any authentication or authorization checks, allowing any unauthenticated user to download images belonging to any flow by knowing (or guessing) the flow ID and file name.
References
| Link | Resource |
|---|---|
| https://www.tenable.com/security/research/tra-2026-23 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-03-27 15:17
Updated : 2026-06-17 10:58
NVD link : CVE-2026-5022
Mitre link : CVE-2026-5022
CVE.ORG link : CVE-2026-5022
JSON object : View
Products Affected
langflow
- langflow
CWE
CWE-862
Missing Authorization
