CVE-2026-21445: Missing authentication on Langflow API endpoints exposes conversation data
Multiple critical API endpoints in Langflow lacked authentication controls prior to version 1.7.0.dev45, allowing unauthenticated users to read user conversation data and transaction histories and to perform destructive operations such as message deletion. A patch is available in version 1.7.0.dev45.
Disclosed 2 January 2026 · Record updated 13 September 2026
Impact
Unauthenticated access to sensitive user conversation data and transaction histories, plus the ability to delete messages and perform other system operations.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-21445
