Skip to content
Noroxi

Langflow records

160 published records for vendor langflow.

All records

160 records
  • Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    langflow · langflowApr 7, 2025

  • Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE

    CriticalCVSS 9.4KEVWeaponizedEPSS 93%

    langflow · langflowDec 5, 2025

  • Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability

    CriticalCVSS 9.8KEVWeaponizedEPSS 64%

    langflow · langflowJan 23, 2026

  • CVE-2026-9198
    78This week

    Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation

    CriticalCVSS 9.8KEVWeaponizedEPSS 29%

    langflow · langflowJul 17, 2026

  • CVE-2026-33017
    74This week

    Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint

    CriticalCVSS 9.3KEVWeaponizedEPSS 25%

    langflow · langflowMar 20, 2026

  • CVE-2026-55255
    63This week

    Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow

    HighCVSS 8.4KEVWeaponizedEPSS 1%

    langflow · langflowJun 23, 2026

  • Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and p

    CriticalCVSS 9.8Proof of conceptEPSS 64%

    langflow · langflowJun 10, 2024

  • Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability

    CriticalCVSS 9.8Proof of conceptEPSS 32%

    langflow · langflowJan 23, 2026

  • Langflow Missing Authentication on Critical API Endpoints

    HighCVSS 8.8Proof of conceptEPSS 33%

    langflow · langflowJan 2, 2026

  • Langflow code Code Injection Remote Code Execution Vulnerability

    CriticalCVSS 9.8Proof of conceptEPSS 8%

    langflow · langflowJan 23, 2026

  • Langflow Privilege Escalation

    HighCVSS 8.8No exploitEPSS 21%

    langflow · langflowJul 30, 2024

  • Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement

    CriticalCVSS 9.9WeaponizedEPSS 3%

    langflow · langflowAug 28, 2026

  • Unauthenticated Superuser Token Issuance via Auto-Login Endpoint

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    langflow · langflowJul 17, 2026

  • Langflow has Remote Code Execution in CSV Agent

    CriticalCVSS 9.8WeaponizedEPSS 2%

    langflow · langflowFeb 25, 2026

  • Unauthenticated Remote Code Execution in Langflow OSS PythonREPLComponent via Builtins Injection

    CriticalCVSS 10.0No exploitEPSS 1%

    langflow · langflowJun 22, 2026

  • Unauthenticated Server-Side RCE via PythonCodeStructuredTool in Public Flows

    CriticalCVSS 10.0Proof of conceptEPSS 1%

    langflow · langflowJun 30, 2026

  • langflow <=1.0.18 is vulnerable to Remote Code Execution (RCE) as any component provided the code functionality and the components run on th

    CriticalCVSS 9.8Proof of conceptEPSS 2%

    langflow · langflowNov 4, 2024

  • langflow v1.0.12 was discovered to contain a remote code execution (RCE) vulnerability via the PythonCodeTool component.

    CriticalCVSS 9.8No exploitEPSS 1%

    langflow · langflowOct 31, 2024

  • Langflow has an Arbitrary File Write (RCE) via v2 API

    CriticalCVSS 9.9No exploitEPSS 1%

    langflow · langflowMar 24, 2026

  • CVE-2026-8505
    39Monitor

    Authentication Bypass in Webhook Endpoints Allowed Unauthorized Flow Execution

    CriticalCVSS 9.8No exploitEPSS 1%

    langflow · langflowJul 17, 2026

  • CVE-2026-8476
    39Monitor

    Disk Cache Deserialization Remote Code Execution Vulnerability

    CriticalCVSS 9.9No exploitEPSS 1%

    langflow · langflowJul 17, 2026

  • Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpoints

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    langflow · langflowJul 30, 2026

  • CVE-2026-7524
    39Monitor

    Path Traversal Vulnerability in File Processing Components Allows Unauthorized File System Access and Potential Remote Code Execution

    CriticalCVSS 9.8No exploitEPSS 1%

    langflow · langflowMay 27, 2026

  • CVE-2026-8481
    39Monitor

    Remote Code Execution via Code Validation Endpoint

    CriticalCVSS 9.9No exploitEPSS 1%

    langflow · langflowJul 17, 2026

  • Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards

    CriticalCVSS 9.8No exploitEPSS 1%

    langflow · langflowSep 10, 2026