AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-8505.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSCRITICAL / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 05, 2026

Disclosure summary

### Summary A vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses API key validation when the `WEBHOOK_AUTH_ENABLE` configuration is set to `False`. This allows a remote attacker who knows a flow's UUID to execute it as if they were the owner, potentially leading to Remote Code Execution (RCE) or Denial of Service (DoS). ### Details The `WEBHOOK_AUTH_ENABLE` setting was introduced in v1.7.0 (#9139) with a default of `False`. The root cause is in the webhook authentication path, `AuthService.get_webhook_user` (`src/backend/base/langflow/services/auth/service.py`; the thin wrapper in `src/backend/base/langflow/services/auth/utils.py` just delegates to it): ```python async def get_webhook_user(self, flow_id: str, request: Request) -> UserRead: settings_service = self.settings ... # VULNERABILITY: If this setting is False (default in = 1.7.0,

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-cf6m-vc3m-7cgm

Open original source · Updated Oct 05, 2026

Langflow: Unauthenticated Flow Execution via Webhook Authentication Bypass

Source severity: CRITICAL / 0

EcosystemPackageAffected rangeFirst patched
piplangflow>= 1.7.0,1.9.1

Original records & references

PUBLISHED 2026-10-05T18:31:22-04:00
MODIFIED 2026-10-05T18:31:23-04:00
INGESTED 2026-10-06T11:45:33-04:00