CVE-2026-5025: Langflow

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

The '/logs' and '/logs-stream' endpoints in the log router allow any authenticated user to read the full application log buffer. These endpoints only require basic authentication ('get_current_active_user') without any privilege checks (e.g., 'is_superuser').

Affected products

  • Langflow Langflow: affected versions not specified

Published 2026-03-27. Last modified 2026-06-17.