CVE-2026-33053
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
20/03/2026
Last modified:
20/03/2026
Description
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the delete_api_key_route() endpoint accepts an api_key_id path parameter and deletes it with only a generic authentication check (get_current_active_user dependency). However, the delete_api_key() CRUD function does NOT verify that the API key belongs to the current user before deletion.
Impact
Base Score 4.0
6.10
Severity 4.0
MEDIUM
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* | 1.9.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



