Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 2 min 127 bronnen 1 kritiek 2 vandaag
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2026-8505

CRITICAL · 9.8 CVSS Gepubliceerd: CWE-306

Beschrijving NL

IBM Langflow Oss 1.0.0 tot 1.10.0 heeft een kwetsbaarheid in de webhook-authenticatielogica van Langflow, waardoor niet-geverifieerde gebruikers de uitvoering van elke stroom kunnen activeren. Het systeem omzeilt ten onrechte de validatie van de API-sleutel wanneer de configuratie WEBHOOK_AUTH_ENABLE is ingesteld op False (wat de standaardinstelling is). Hierdoor kan een externe aanvaller die de UUID van een stroom kent, deze uitvoeren alsof hij de eigenaar is, wat mogelijk leidt tot Remote Code Execution (RCE).

Origineel (Engels) tonen

IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses API key validation when the WEBHOOK_AUTH_ENABLE configuration is set to False (which is the default setting). This allows a remote attacker who knows a flow's UUID to execute it as if they were the owner, potentially leading to Remote Code Execution (RCE).

Vendors

Langflow Apple Linux Microsoft

Affected products

Langflow Macos Linux Kernel Windows

References