Записи Langflow
160 опубликованных записей вендора langflow.
Профиль для исследователя
- Попали в KEV
- 6 · 3,8 %
- С эксплойтом
- 9 · 5,6 %
- Pre-auth RCE
- 29
- С записью об исправлении
- 15,6 %
- Медиана: публикация → KEV
- 23 дн.
Повторяющиеся классы
- CWE-94 Improper Control of Generation of Code ('Code Injection')32
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')26
- CWE-918 Server-Side Request Forgery (SSRF)17
- CWE-639 Authorization Bypass Through User-Controlled Key16
- CWE-306 Missing Authentication for Critical Function7
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')7
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
160 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2025-3248Готовый эксплойт | Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/codelangflow · langflow · CWE-306 | Критическая9,8 | KEV | 100,0 % | 7 апр. 2025 г. |
95Срочно | CVE-2025-34291Готовый эксплойт | Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCElangflow · langflow · CWE-346 | Критическая9,4 | KEV | 92,8 % | 5 дек. 2025 г. |
88Срочно | CVE-2026-0770Готовый эксплойт | Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerabilitylangflow · langflow · CWE-829 | Критическая9,8 | KEV | 63,8 % | 23 янв. 2026 г. |
78На этой неделе | CVE-2026-9198Готовый эксплойт | Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validationlangflow · langflow · CWE-94 | Критическая9,8 | KEV | 28,7 % | 17 июл. 2026 г. |
74На этой неделе | CVE-2026-33017Готовый эксплойт | Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpointlangflow · langflow · CWE-94 | Критическая9,3 | KEV | 24,8 % | 20 мар. 2026 г. |
63На этой неделе | CVE-2026-55255Готовый эксплойт | Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flowlangflow · langflow · CWE-639 | Высокая8,4 | KEV | 0,9 % | 23 июн. 2026 г. |
58В плане | CVE-2024-37014Proof of concept | Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and plangflow · langflow · CWE-94 | Критическая9,8 | — | 63,7 % | 10 июн. 2024 г. |
49В плане | CVE-2026-0769Proof of concept | Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerabilitylangflow · langflow · CWE-95 | Критическая9,8 | — | 32,3 % | 23 янв. 2026 г. |
45В плане | CVE-2026-21445Proof of concept | Langflow Missing Authentication on Critical API Endpointslangflow · langflow · CWE-306 | Высокая8,8 | — | 33,3 % | 2 янв. 2026 г. |
42В плане | CVE-2026-0768Proof of concept | Langflow code Code Injection Remote Code Execution Vulnerabilitylangflow · langflow · CWE-94 | Критическая9,8 | — | 8,5 % | 23 янв. 2026 г. |
41В плане | CVE-2024-7297Эксплойта нет | Langflow Privilege Escalationlangflow · langflow · CWE-913 | Высокая8,8 | — | 21,3 % | 30 июл. 2024 г. |
40В плане | CVE-2026-19295Готовый эксплойт | Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcementlangflow · langflow · CWE-95 | Критическая9,9 | — | 3,3 % | 28 авг. 2026 г. |
40В плане | CVE-2026-9103Proof of concept | Unauthenticated Superuser Token Issuance via Auto-Login Endpointlangflow · langflow · CWE-306 | Критическая9,8 | — | 3,2 % | 17 июл. 2026 г. |
40В плане | CVE-2026-27966Готовый эксплойт | Langflow has Remote Code Execution in CSV Agentlangflow · langflow · CWE-94 | Критическая9,8 | — | 2,5 % | 25 февр. 2026 г. |
40В плане | CVE-2026-10561Эксплойта нет | Unauthenticated Remote Code Execution in Langflow OSS PythonREPLComponent via Builtins Injectionlangflow · langflow · CWE-94 | Критическая10,0 | — | 1,0 % | 22 июн. 2026 г. |
40В плане | CVE-2026-10134Proof of concept | Unauthenticated Server-Side RCE via PythonCodeStructuredTool in Public Flowslangflow · langflow · CWE-94 | Критическая10,0 | — | 0,6 % | 30 июн. 2026 г. |
39Наблюдать | CVE-2024-48061Proof of concept | langflow <=1.0.18 is vulnerable to Remote Code Execution (RCE) as any component provided the code functionality and the components run on thlangflow · langflow · CWE-94 | Критическая9,8 | — | 1,5 % | 4 нояб. 2024 г. |
39Наблюдать | CVE-2024-42835Эксплойта нет | langflow v1.0.12 was discovered to contain a remote code execution (RCE) vulnerability via the PythonCodeTool component.langflow · langflow | Критическая9,8 | — | 1,2 % | 31 окт. 2024 г. |
39Наблюдать | CVE-2026-33309Эксплойта нет | Langflow has an Arbitrary File Write (RCE) via v2 APIlangflow · langflow · CWE-22 | Критическая9,9 | — | 1,0 % | 24 мар. 2026 г. |
39Наблюдать | CVE-2026-8505Эксплойта нет | Authentication Bypass in Webhook Endpoints Allowed Unauthorized Flow Executionlangflow · langflow · CWE-306 | Критическая9,8 | — | 1,0 % | 17 июл. 2026 г. |
39Наблюдать | CVE-2026-8476Эксплойта нет | Disk Cache Deserialization Remote Code Execution Vulnerabilitylangflow · langflow · CWE-502 | Критическая9,9 | — | 1,0 % | 17 июл. 2026 г. |
39Наблюдать | CVE-2026-12940Proof of concept | Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpointslangflow · langflow · CWE-78 | Критическая9,8 | — | 0,9 % | 30 июл. 2026 г. |
39Наблюдать | CVE-2026-7524Эксплойта нет | Path Traversal Vulnerability in File Processing Components Allows Unauthorized File System Access and Potential Remote Code Executionlangflow · langflow · CWE-22 | Критическая9,8 | — | 0,9 % | 27 мая 2026 г. |
39Наблюдать | CVE-2026-8481Эксплойта нет | Remote Code Execution via Code Validation Endpointlangflow · langflow · CWE-94 | Критическая9,9 | — | 0,9 % | 17 июл. 2026 г. |
39Наблюдать | CVE-2026-81204Эксплойта нет | Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guardslangflow · langflow · CWE-94 | Критическая9,8 | — | 0,9 % | 10 сент. 2026 г. |
- CVE-2025-324899Срочно
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %langflow · langflow7 апр. 2025 г.
- CVE-2025-3429195Срочно
Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE
КритическаяCVSS 9,4KEVГотовый эксплойтEPSS 93 %langflow · langflow5 дек. 2025 г.
- CVE-2026-077088Срочно
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 64 %langflow · langflow23 янв. 2026 г.
- CVE-2026-919878На этой неделе
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 29 %langflow · langflow17 июл. 2026 г.
- CVE-2026-3301774На этой неделе
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
КритическаяCVSS 9,3KEVГотовый эксплойтEPSS 25 %langflow · langflow20 мар. 2026 г.
- CVE-2026-5525563На этой неделе
Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
ВысокаяCVSS 8,4KEVГотовый эксплойтEPSS 1 %langflow · langflow23 июн. 2026 г.
- CVE-2024-3701458В плане
Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and p
КритическаяCVSS 9,8Proof of conceptEPSS 64 %langflow · langflow10 июн. 2024 г.
- CVE-2026-076949В плане
Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability
КритическаяCVSS 9,8Proof of conceptEPSS 32 %langflow · langflow23 янв. 2026 г.
- CVE-2026-2144545В плане
Langflow Missing Authentication on Critical API Endpoints
ВысокаяCVSS 8,8Proof of conceptEPSS 33 %langflow · langflow2 янв. 2026 г.
- CVE-2026-076842В плане
Langflow code Code Injection Remote Code Execution Vulnerability
КритическаяCVSS 9,8Proof of conceptEPSS 8 %langflow · langflow23 янв. 2026 г.
- CVE-2024-729741В плане
Langflow Privilege Escalation
ВысокаяCVSS 8,8Эксплойта нетEPSS 21 %langflow · langflow30 июл. 2024 г.
- CVE-2026-1929540В плане
Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement
КритическаяCVSS 9,9Готовый эксплойтEPSS 3 %langflow · langflow28 авг. 2026 г.
- CVE-2026-910340В плане
Unauthenticated Superuser Token Issuance via Auto-Login Endpoint
КритическаяCVSS 9,8Proof of conceptEPSS 3 %langflow · langflow17 июл. 2026 г.
- CVE-2026-2796640В плане
Langflow has Remote Code Execution in CSV Agent
КритическаяCVSS 9,8Готовый эксплойтEPSS 2 %langflow · langflow25 февр. 2026 г.
- CVE-2026-1056140В плане
Unauthenticated Remote Code Execution in Langflow OSS PythonREPLComponent via Builtins Injection
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %langflow · langflow22 июн. 2026 г.
- CVE-2026-1013440В плане
Unauthenticated Server-Side RCE via PythonCodeStructuredTool in Public Flows
КритическаяCVSS 10,0Proof of conceptEPSS 1 %langflow · langflow30 июн. 2026 г.
- CVE-2024-4806139Наблюдать
langflow <=1.0.18 is vulnerable to Remote Code Execution (RCE) as any component provided the code functionality and the components run on th
КритическаяCVSS 9,8Proof of conceptEPSS 2 %langflow · langflow4 нояб. 2024 г.
- CVE-2024-4283539Наблюдать
langflow v1.0.12 was discovered to contain a remote code execution (RCE) vulnerability via the PythonCodeTool component.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %langflow · langflow31 окт. 2024 г.
- CVE-2026-3330939Наблюдать
Langflow has an Arbitrary File Write (RCE) via v2 API
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %langflow · langflow24 мар. 2026 г.
- CVE-2026-850539Наблюдать
Authentication Bypass in Webhook Endpoints Allowed Unauthorized Flow Execution
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %langflow · langflow17 июл. 2026 г.
- CVE-2026-847639Наблюдать
Disk Cache Deserialization Remote Code Execution Vulnerability
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %langflow · langflow17 июл. 2026 г.
- CVE-2026-1294039Наблюдать
Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpoints
КритическаяCVSS 9,8Proof of conceptEPSS 1 %langflow · langflow30 июл. 2026 г.
- CVE-2026-752439Наблюдать
Path Traversal Vulnerability in File Processing Components Allows Unauthorized File System Access and Potential Remote Code Execution
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %langflow · langflow27 мая 2026 г.
- CVE-2026-848139Наблюдать
Remote Code Execution via Code Validation Endpoint
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %langflow · langflow17 июл. 2026 г.
- CVE-2026-8120439Наблюдать
Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %langflow · langflow10 сент. 2026 г.