OSV 1.4.0 · github-reviewed · 修改于 2026-06-20 05:17
发布时间
2026-06-20 05:17
GitHub 审查时间
2026-06-20 05:17
NVD 发布时间
—
源文件
advisories/github-reviewed/2026/06/GHSA-7hw8-6q6r-4276/GHSA-7hw8-6q6r-4276.json
The logout button does not clear the session. The previous user stays logged in unless another user explicitly logs in.
Not in auto login mode. Hosted on localhost. access_token_lf remains present in both Local Storage and Cookies. refresh_token_lf remains present in Cookies.
Root cause: the /logout endpoint deleted the authentication cookies without matching the original httponly/samesite/secure/domain parameters, so the browser kept them; additionally the frontend did not clear the auth cookies on logout.
LANGFLOW_AUTO_LOGIN: "False"
LANGFLOW_SUPERUSER: <set>
LANGFLOW_SUPERUSER_PASSWORD: <set>
LANGFLOW_SECRET_KEY: <set>
LANGFLOW_NEW_USER_IS_ACTIVE: "False"
LANGFLOW_ENABLE_SUPERUSER_CLI: "False"
Click Logout. Hit refresh to return to previous screen.
Users on shared computers may falsely believe they have terminated their session.
Fixed in 1.7.0 (PRs #10527 and #10528). The logout endpoint now deletes the auth cookies using the same parameters they were created with, and the frontend clears the auth cookies on logout. Upgrade to 1.7.0 or later.