IBM Langflow OSS 1.0.0 through 1.8.4 could allow any user to supply a flow_id to read transaction logs and vertex build data belonging to other users, and to delete persisted vertex build data for another user's flow.
IBM recommends addressing the vulnerability now by upgrading to Langflow OSS 1.9.0 or newer: https://github.com/langflow-ai/langflow