Description

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.7.0, the logout button does not clear the session. The previous user stays logged in unless another user explicitly logs in. This vulnerability is fixed in 1.7.0.

Severity (CVSS)

Base score6.1
SeverityMedium
VersionCVSS 3.1
VectorCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Provided byCNA

Weaknesses

  • CWE-613 — CWE-613: Insufficient Session Expiration

Affected products

VendorProductVersions
langflow-ailangflow< 1.7.0

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 24 Jun 2026 09:35 UTC.