CVE-2026-34046 | langflow-ai langflow up to 1.5.0 flows.py _read_flow authorization (GHSA-8c4j-f57c-35cf)
A vulnerability classified as critical was found in langflow-ai langflow up to 1.5.0. Impacted is the function _read_flow of the file src/backend/base/langflow/api/v1/flows.py. The manipulation results in authorization bypass.
This vulnerability was named CVE-2026-34046. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.