CVE-2026-5025: Langflow
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
The '/logs' and '/logs-stream' endpoints in the log router allow any authenticated user to read the full application log buffer. These endpoints only require basic authentication ('get_current_active_user') without any privilege checks (e.g., 'is_superuser').
Affected products
- Langflow Langflow: affected versions not specified
Published 2026-03-27. Last modified 2026-06-17.