{"id":"GHSA-9cc5-j3qq-69gv","summary":"Duplicate Advisory: Unauthenticated Flow Execution via Webhook Authentication Bypass","details":"## Duplicate Advisory\n\nThis advisory has been withdrawn because it is a duplicate of GHSA-cf6m-vc3m-7cgm. This link is maintained to preserve external references.\n\n## Original Description\nIBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses API key validation when the WEBHOOK_AUTH_ENABLE configuration is set to False (which is the default setting). This allows a remote attacker who knows a flow's UUID to execute it as if they were the owner, potentially leading to Remote Code Execution (RCE).","modified":"2026-10-05T22:45:05.550440130Z","published":"2026-07-17T21:31:45Z","withdrawn":"2026-10-05T22:31:17Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-10-05T22:31:17Z","nvd_published_at":"2026-07-17T20:17:31Z","cwe_ids":["CWE-306"],"severity":"CRITICAL"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8505"},{"type":"WEB","url":"https://www.ibm.com/support/pages/node/7278921"}],"affected":[{"package":{"name":"langflow","ecosystem":"PyPI","purl":"pkg:pypi/langflow"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.7.0"},{"last_affected":"1.9.0"}]}],"versions":["1.7.0","1.7.1","1.7.2","1.7.3","1.8.0","1.8.0rc0","1.8.0rc1","1.8.0rc2","1.8.0rc3","1.8.0rc4","1.8.0rc5","1.8.0rc6","1.8.1","1.8.2","1.8.3","1.8.3rc0","1.8.4","1.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-9cc5-j3qq-69gv/GHSA-9cc5-j3qq-69gv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}