How to use this reference
The documented fix carries authenticated context into object resolution, constrains project membership, and scopes discovery results. Editorial lesson: connection admission and storage containment cannot replace per-resource authorization; compare policy across every interface to the same object.
Before reading
- Object ownership and project membership models
- MCP resource handling and application storage separation
Context and limits
- Source prerequisites include authentication-enabled deployments, an accessible owned project, and another user’s uploaded flow-backed file.
- The maintainer corrects affected versions to 1.6.8–1.9.0 and identifies 1.9.1, released April 24, 2026, as fixed. September publication is not patch timing.
- The September 22 triage update reports regression coverage; this review did not independently run it. No observed production compromise or award is established.
- Conceptual defensive summary; public disclosure grants no testing authorization.
- The advisory credits R1ZZG0D as Reporter, andifilhohub as Analyst, and erichare as Remediation developer. Its header identifies andifilhohub as the publishing account. No explicit author byline is shown, so named authors remain unestablished rather than inferred from those roles.
Sources and provenance
- Authenticated Cross-Project File Disclosure via Unscoped MCP Resource Handlers Langflow · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.