{"id":"GHSA-cf6m-vc3m-7cgm","summary":"Langflow: Unauthenticated Flow Execution via Webhook Authentication Bypass","details":"### Summary\nA vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses API key validation when the `WEBHOOK_AUTH_ENABLE` configuration is set to `False`. This allows a remote attacker who knows a flow's UUID to execute it as if they were the owner, potentially leading to Remote Code Execution (RCE) or Denial of Service (DoS).\n\n### Details\nThe `WEBHOOK_AUTH_ENABLE` setting was introduced in v1.7.0 (#9139) with a default of `False`. The root cause is in the webhook authentication path, `AuthService.get_webhook_user` (`src/backend/base/langflow/services/auth/service.py`; the thin wrapper in `src/backend/base/langflow/services/auth/utils.py` just delegates to it):\n\n```python\nasync def get_webhook_user(self, flow_id: str, request: Request) -\u003e UserRead:\n    settings_service = self.settings\n    ...\n    # VULNERABILITY: If this setting is False (default in \u003c= 1.9.0), it returns\n    # the flow owner WITHOUT checking the API Key in the request.\n    if not settings_service.auth_settings.WEBHOOK_AUTH_ENABLE:\n        try:\n            flow_owner = await get_user_by_flow_id_or_endpoint_name(flow_id)\n            return flow_owner\n```\n\nBy default (v1.7.0 through v1.9.0), Langflow treats `WEBHOOK_AUTH_ENABLE` as `False`, meaning all webhook endpoints are public. This relies exclusively on the secrecy of the `flow_id` (UUID), which is an insecure practice (Security by Obscurity).\n\nA related report, GHSA-6g4m-v5q2-475v, demonstrated a concrete RCE chain through this same bypass using the `PythonCodeStructuredTool` component (`exec()` on flow-authored Python code). That report is a duplicate of this root cause and has been closed in favor of this advisory; credit for that PoC has been added here.\n\n### PoC\n1. Identify a valid `flow_id` for a flow that performs a sensitive action (e.g., sending an email, writing to a database, or executing a Python script).\n2. Execute a POST request to the webhook endpoint without any `Authorization` header or API Key:\n```bash\ncurl -X POST \"http://\u003cserver-ip\u003e:7860/api/v1/webhook/\u003cflow_id\u003e\" \\\n     -H \"Content-Type: application/json\" \\\n     -d '{\"input\": \"payload\"}'\n```\n3. Verify that the flow execution is triggered and the action is performed on the server.\n\n### Impact\nThis is a **High-severity Authentication Bypass**.\n- **Remote Code Execution (RCE)**: Flows often contain components that execute arbitrary Python code. An attacker can leverage this to gain full control over the server.\n- **Denial of Service (DoS)**: Attackers can exhaust system resources by triggering heavy flows concurrently.\n- **Data Integrity**: Unauthorized execution of flows can lead to unintended modification of databases or external systems connected via the flow.\n\n### Affected versions\n`\u003e= 1.7.0, \u003c= 1.9.0` (the range in which `WEBHOOK_AUTH_ENABLE` existed and defaulted to `False`).\n\n### Fix\nFixed in **v1.9.1** by [PR #12845](https://github.com/langflow-ai/langflow/pull/12845) — `fix(security): default WEBHOOK_AUTH_ENABLE to True`. The setting's default changed from `False` to `True`, so webhook endpoints now require API key authentication and ownership validation by default, unless an operator explicitly opts out via `LANGFLOW_WEBHOOK_AUTH_ENABLE=false`.","aliases":["CVE-2026-8505"],"modified":"2026-10-05T22:45:06.599225017Z","published":"2026-10-05T22:31:22Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-306"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-10-05T22:31:22Z"},"references":[{"type":"WEB","url":"https://github.com/langflow-ai/langflow/security/advisories/GHSA-cf6m-vc3m-7cgm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8505"},{"type":"WEB","url":"https://github.com/langflow-ai/langflow/pull/12845"},{"type":"WEB","url":"https://github.com/langflow-ai/langflow/commit/cb6f7508dda83ead9c3e4417e96e4b5bd9a260c3"},{"type":"PACKAGE","url":"https://github.com/langflow-ai/langflow"},{"type":"WEB","url":"https://github.com/langflow-ai/langflow/releases/tag/v1.9.1"},{"type":"WEB","url":"https://www.ibm.com/support/pages/node/7278921"}],"affected":[{"package":{"name":"langflow","ecosystem":"PyPI","purl":"pkg:pypi/langflow"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.7.0"},{"fixed":"1.9.1"}]}],"versions":["1.7.0","1.7.1","1.7.2","1.7.3","1.8.0","1.8.0rc0","1.8.0rc1","1.8.0rc2","1.8.0rc3","1.8.0rc4","1.8.0rc5","1.8.0rc6","1.8.1","1.8.2","1.8.3","1.8.3rc0","1.8.4","1.9.0"],"database_specific":{"last_known_affected_version_range":"\u003c= 1.9.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-cf6m-vc3m-7cgm/GHSA-cf6m-vc3m-7cgm.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}