<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T04:52:24.606890+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-33053</id>
    <title>CVE-2026-33053 — Langflow has Missing Ownership Verification in API Key Deletion (IDOR)</title>
    <updated>2026-10-03T04:52:24.608879+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> langflow-ai langflow</p>
<p>Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the delete_api_key_route() endpoint accepts an api_key_id path parameter and deletes it with only a generic authentication check (get_current_active_user dependency). However, the delete_api_key() CRUD function does NOT verify that the API key belongs to the current user before deletion.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-33053"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rf6x-r45m-xv3w</id>
    <title>GHSA-rf6x-r45m-xv3w — Langflow is Missing Ownership Verification in API Key Deletion (IDOR)</title>
    <updated>2026-10-03T04:52:24.608947+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: langflow</p>
<p>**Detection Method:** Kolega.dev Deep Code Scan</p>
<p>| Attribute | Value |
|---|---|
| Location | src/backend/base/langflow/api/v1/api_key.py:44-53 |
| Practical Exploitability | High |
| Developer Approver | faizan@kolega.ai |</p>
<p>### Description
The delete_api_key_route() endpoint accepts an api_key_id path parameter and deletes it with only a generic authentication check (get_current_active_user dependency). However, the delete_api_key() CRUD function does NOT verify that the API key belongs to the current user before deletion.</p>
<p>### Affected Code
```
@router.delete("/{api_key_id}", dependencies=[Depends(auth_utils.get_current_active_user)])
async def delete_api_key_route(
    api_key_id: UUID,
    db: DbSession,
):
    try:
        await delete_api_key(db, api_key_id)
    except Exception as e:
        raise HTTPException(status_code=400, detail=str(e)) from e
    return {"detail": "API Key deleted"}
```</p>
<p>### Evidence
In crud.py lines 44-49, delete_api_key() retrieves the API key by ID and deletes it without checking if the key belongs to the authenticated user. The endpoint also doesn't pass the current_user to the delete function for verification.</p>
<p>### Impact
An authenticated attacker can enumerate and delete API keys belonging to other users by guessing or discovering their API key IDs. This allows account takeover, denial of service, and disruption of other users' integrations.</p>
<p>### Recommendation
Modify the delete_api_key endpoint and function: (1) Pass current_user to the…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rf6x-r45m-xv3w"/>
  </entry>
</feed>
