Langflow records
160 published records for vendor langflow.
Researcher profile
- Entered KEV
- 6 · 3.8%
- Weaponized
- 9 · 5.6%
- Pre-auth RCE
- 29
- With a fix record
- 15.6%
- Median publish → KEV
- 23 days
Recurring classes
- CWE-94 Improper Control of Generation of Code ('Code Injection')32
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')26
- CWE-918 Server-Side Request Forgery (SSRF)17
- CWE-639 Authorization Bypass Through User-Controlled Key16
- CWE-306 Missing Authentication for Critical Function7
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')7
The weakness classes this vendor ships most often: where to look.
CWEAll records
160 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2025-3248Weaponized | Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/codelangflow · langflow · CWE-306 | Critical9.8 | KEV | 100.0% | Apr 7, 2025 |
95Now | CVE-2025-34291Weaponized | Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCElangflow · langflow · CWE-346 | Critical9.4 | KEV | 92.8% | Dec 5, 2025 |
88Now | CVE-2026-0770Weaponized | Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerabilitylangflow · langflow · CWE-829 | Critical9.8 | KEV | 63.8% | Jan 23, 2026 |
78This week | CVE-2026-9198Weaponized | Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validationlangflow · langflow · CWE-94 | Critical9.8 | KEV | 28.7% | Jul 17, 2026 |
74This week | CVE-2026-33017Weaponized | Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpointlangflow · langflow · CWE-94 | Critical9.3 | KEV | 24.8% | Mar 20, 2026 |
63This week | CVE-2026-55255Weaponized | Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flowlangflow · langflow · CWE-639 | High8.4 | KEV | 0.9% | Jun 23, 2026 |
58Plan | CVE-2024-37014Proof of concept | Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and plangflow · langflow · CWE-94 | Critical9.8 | — | 63.7% | Jun 10, 2024 |
49Plan | CVE-2026-0769Proof of concept | Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerabilitylangflow · langflow · CWE-95 | Critical9.8 | — | 32.3% | Jan 23, 2026 |
45Plan | CVE-2026-21445Proof of concept | Langflow Missing Authentication on Critical API Endpointslangflow · langflow · CWE-306 | High8.8 | — | 33.3% | Jan 2, 2026 |
42Plan | CVE-2026-0768Proof of concept | Langflow code Code Injection Remote Code Execution Vulnerabilitylangflow · langflow · CWE-94 | Critical9.8 | — | 8.5% | Jan 23, 2026 |
41Plan | CVE-2024-7297No exploit | Langflow Privilege Escalationlangflow · langflow · CWE-913 | High8.8 | — | 21.3% | Jul 30, 2024 |
40Plan | CVE-2026-19295Weaponized | Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcementlangflow · langflow · CWE-95 | Critical9.9 | — | 3.3% | Aug 28, 2026 |
40Plan | CVE-2026-9103Proof of concept | Unauthenticated Superuser Token Issuance via Auto-Login Endpointlangflow · langflow · CWE-306 | Critical9.8 | — | 3.2% | Jul 17, 2026 |
40Plan | CVE-2026-27966Weaponized | Langflow has Remote Code Execution in CSV Agentlangflow · langflow · CWE-94 | Critical9.8 | — | 2.5% | Feb 25, 2026 |
40Plan | CVE-2026-10561No exploit | Unauthenticated Remote Code Execution in Langflow OSS PythonREPLComponent via Builtins Injectionlangflow · langflow · CWE-94 | Critical10.0 | — | 1.0% | Jun 22, 2026 |
40Plan | CVE-2026-10134Proof of concept | Unauthenticated Server-Side RCE via PythonCodeStructuredTool in Public Flowslangflow · langflow · CWE-94 | Critical10.0 | — | 0.6% | Jun 30, 2026 |
39Monitor | CVE-2024-48061Proof of concept | langflow <=1.0.18 is vulnerable to Remote Code Execution (RCE) as any component provided the code functionality and the components run on thlangflow · langflow · CWE-94 | Critical9.8 | — | 1.5% | Nov 4, 2024 |
39Monitor | CVE-2024-42835No exploit | langflow v1.0.12 was discovered to contain a remote code execution (RCE) vulnerability via the PythonCodeTool component.langflow · langflow | Critical9.8 | — | 1.2% | Oct 31, 2024 |
39Monitor | CVE-2026-33309No exploit | Langflow has an Arbitrary File Write (RCE) via v2 APIlangflow · langflow · CWE-22 | Critical9.9 | — | 1.0% | Mar 24, 2026 |
39Monitor | CVE-2026-8505No exploit | Authentication Bypass in Webhook Endpoints Allowed Unauthorized Flow Executionlangflow · langflow · CWE-306 | Critical9.8 | — | 1.0% | Jul 17, 2026 |
39Monitor | CVE-2026-8476No exploit | Disk Cache Deserialization Remote Code Execution Vulnerabilitylangflow · langflow · CWE-502 | Critical9.9 | — | 1.0% | Jul 17, 2026 |
39Monitor | CVE-2026-12940Proof of concept | Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpointslangflow · langflow · CWE-78 | Critical9.8 | — | 0.9% | Jul 30, 2026 |
39Monitor | CVE-2026-7524No exploit | Path Traversal Vulnerability in File Processing Components Allows Unauthorized File System Access and Potential Remote Code Executionlangflow · langflow · CWE-22 | Critical9.8 | — | 0.9% | May 27, 2026 |
39Monitor | CVE-2026-8481No exploit | Remote Code Execution via Code Validation Endpointlangflow · langflow · CWE-94 | Critical9.9 | — | 0.9% | Jul 17, 2026 |
39Monitor | CVE-2026-81204No exploit | Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guardslangflow · langflow · CWE-94 | Critical9.8 | — | 0.9% | Sep 10, 2026 |
- CVE-2025-324899Now
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
CriticalCVSS 9.8KEVWeaponizedEPSS 100%langflow · langflowApr 7, 2025
- CVE-2025-3429195Now
Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE
CriticalCVSS 9.4KEVWeaponizedEPSS 93%langflow · langflowDec 5, 2025
- CVE-2026-077088Now
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
CriticalCVSS 9.8KEVWeaponizedEPSS 64%langflow · langflowJan 23, 2026
- CVE-2026-919878This week
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
CriticalCVSS 9.8KEVWeaponizedEPSS 29%langflow · langflowJul 17, 2026
- CVE-2026-3301774This week
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
CriticalCVSS 9.3KEVWeaponizedEPSS 25%langflow · langflowMar 20, 2026
- CVE-2026-5525563This week
Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
HighCVSS 8.4KEVWeaponizedEPSS 1%langflow · langflowJun 23, 2026
- CVE-2024-3701458Plan
Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and p
CriticalCVSS 9.8Proof of conceptEPSS 64%langflow · langflowJun 10, 2024
- CVE-2026-076949Plan
Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 32%langflow · langflowJan 23, 2026
- CVE-2026-2144545Plan
Langflow Missing Authentication on Critical API Endpoints
HighCVSS 8.8Proof of conceptEPSS 33%langflow · langflowJan 2, 2026
- CVE-2026-076842Plan
Langflow code Code Injection Remote Code Execution Vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 8%langflow · langflowJan 23, 2026
- CVE-2024-729741Plan
Langflow Privilege Escalation
HighCVSS 8.8No exploitEPSS 21%langflow · langflowJul 30, 2024
- CVE-2026-1929540Plan
Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement
CriticalCVSS 9.9WeaponizedEPSS 3%langflow · langflowAug 28, 2026
- CVE-2026-910340Plan
Unauthenticated Superuser Token Issuance via Auto-Login Endpoint
CriticalCVSS 9.8Proof of conceptEPSS 3%langflow · langflowJul 17, 2026
- CVE-2026-2796640Plan
Langflow has Remote Code Execution in CSV Agent
CriticalCVSS 9.8WeaponizedEPSS 2%langflow · langflowFeb 25, 2026
- CVE-2026-1056140Plan
Unauthenticated Remote Code Execution in Langflow OSS PythonREPLComponent via Builtins Injection
CriticalCVSS 10.0No exploitEPSS 1%langflow · langflowJun 22, 2026
- CVE-2026-1013440Plan
Unauthenticated Server-Side RCE via PythonCodeStructuredTool in Public Flows
CriticalCVSS 10.0Proof of conceptEPSS 1%langflow · langflowJun 30, 2026
- CVE-2024-4806139Monitor
langflow <=1.0.18 is vulnerable to Remote Code Execution (RCE) as any component provided the code functionality and the components run on th
CriticalCVSS 9.8Proof of conceptEPSS 2%langflow · langflowNov 4, 2024
- CVE-2024-4283539Monitor
langflow v1.0.12 was discovered to contain a remote code execution (RCE) vulnerability via the PythonCodeTool component.
CriticalCVSS 9.8No exploitEPSS 1%langflow · langflowOct 31, 2024
- CVE-2026-3330939Monitor
Langflow has an Arbitrary File Write (RCE) via v2 API
CriticalCVSS 9.9No exploitEPSS 1%langflow · langflowMar 24, 2026
- CVE-2026-850539Monitor
Authentication Bypass in Webhook Endpoints Allowed Unauthorized Flow Execution
CriticalCVSS 9.8No exploitEPSS 1%langflow · langflowJul 17, 2026
- CVE-2026-847639Monitor
Disk Cache Deserialization Remote Code Execution Vulnerability
CriticalCVSS 9.9No exploitEPSS 1%langflow · langflowJul 17, 2026
- CVE-2026-1294039Monitor
Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpoints
CriticalCVSS 9.8Proof of conceptEPSS 1%langflow · langflowJul 30, 2026
- CVE-2026-752439Monitor
Path Traversal Vulnerability in File Processing Components Allows Unauthorized File System Access and Potential Remote Code Execution
CriticalCVSS 9.8No exploitEPSS 1%langflow · langflowMay 27, 2026
- CVE-2026-848139Monitor
Remote Code Execution via Code Validation Endpoint
CriticalCVSS 9.9No exploitEPSS 1%langflow · langflowJul 17, 2026
- CVE-2026-8120439Monitor
Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards
CriticalCVSS 9.8No exploitEPSS 1%langflow · langflowSep 10, 2026