The '/api/v1/files/images/{flow_id}/{file_name}' endpoint does not enforce any authentication or authorization checks, allowing any unauthenticated user to download images belonging to any flow by knowing (or guessing) the flow ID and file name.
References
| Link | Resource |
|---|---|
| https://www.tenable.com/security/research/tra-2026-23 | Vendor Advisory |
Configurations
History
20 Apr 2026, 13:00
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.tenable.com/security/research/tra-2026-23 - Vendor Advisory | |
| First Time |
Langflow langflow
Langflow |
|
| CPE | cpe:2.3:a:langflow:langflow:-:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
27 Mar 2026, 15:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-27 15:17
Updated : 2026-04-20 13:00
NVD link : CVE-2026-5022
Mitre link : CVE-2026-5022
CVE.ORG link : CVE-2026-5022
JSON object : View
Products Affected
langflow
- langflow
CWE
CWE-862
Missing Authorization
