BREAKING
CISA Adds Langflow Flaw to KEV
0
CVSS v3.1
0
days
to deadline
0
+
GitHub stars
How the IDOR Bypass Works
1
Login as user
↓
2
Enumerate flow IDs
↓
3
Call /responses
↓
4
Run others' flows
Patch or Discontinue Use
Remediate
By Jul 10
●
Update to 1.9.1+
●
Block external exposure
●
Review auth settings
If not fixed
BOD 26-04
●
Discontinue product use
●
Applies to FCEB agencies
Chained With RCE in the Wild
Update Langflow to 1.9.1 Now
AI NEWS BLITZ
CISA has added a critical Langflow authorization bypass flaw to its Known Exploited Vulnerabilities list.