CVE-2026-8505
Beschrijving NL
IBM Langflow Oss 1.0.0 tot 1.10.0 heeft een kwetsbaarheid in de webhook-authenticatielogica van Langflow, waardoor niet-geverifieerde gebruikers de uitvoering van elke stroom kunnen activeren. Het systeem omzeilt ten onrechte de validatie van de API-sleutel wanneer de configuratie WEBHOOK_AUTH_ENABLE is ingesteld op False (wat de standaardinstelling is). Hierdoor kan een externe aanvaller die de UUID van een stroom kent, deze uitvoeren alsof hij de eigenaar is, wat mogelijk leidt tot Remote Code Execution (RCE).
Origineel (Engels) tonen
IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses API key validation when the WEBHOOK_AUTH_ENABLE configuration is set to False (which is the default setting). This allows a remote attacker who knows a flow's UUID to execute it as if they were the owner, potentially leading to Remote Code Execution (RCE).