CVE-2026-76059Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards Exploitation status Not known exploited Fix YesPublished 09/10/2026 Severity High CVE-2026-78569Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards Exploitation status Not known exploited Fix YesPublished 09/10/2026 Severity High CVE-2026-78571Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards Exploitation status Not known exploited Fix YesPublished 09/10/2026 Severity High CVE-2026-78575Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards Exploitation status Not known exploited Fix YesPublished 09/10/2026 Severity High CVE-2026-79723Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches Exploitation status Not known exploited Fix YesPublished 09/10/2026 Severity Medium CVE-2026-79724Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards Exploitation status Not known exploited Fix YesPublished 09/10/2026 Severity Critical CVE-2026-79725Langflow is vulnerable to unauthorized file system access due to path traversal and missing storage path validation Exploitation status Not known exploited Fix YesPublished 09/10/2026 Severity Medium CVE-2026-79742Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards Exploitation status Not known exploited Fix YesPublished 09/10/2026 Severity High CVE-2026-81204Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards Exploitation status Not known exploited Fix YesPublished 09/10/2026 Severity Critical CVE-2026-81211Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards Exploitation status Not known exploited Fix YesPublished 09/10/2026 Severity High CVE-2026-81941Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards Exploitation status Not known exploited Fix YesPublished 09/10/2026 Severity High CVE-2026-81213Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches Exploitation status Not known exploited Fix YesPublished 09/10/2026 Severity High CVE-2026-81265Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches Exploitation status Not known exploited Fix YesPublished 09/10/2026 Severity High CVE-2026-81268Langflow is vulnerable to authentication bypass and insufficient session expiration Exploitation status Not known exploited Fix YesPublished 09/10/2026 Severity High CVE-2026-81940Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards Exploitation status Not known exploited Fix YesPublished 09/10/2026 Severity High CVE-2026-84889A path traversal vulnerability in file handling components could allow an authenticated attacker to write files to arbitrary locations on the server filesystem Exploitation status Not known exploited Fix YesPublished 09/10/2026 Severity High CVE-2026-85025Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards Exploitation status Not known exploited Fix YesPublished 09/10/2026 Severity Critical CVE-2026-9225Langflow is vulnerable to unauthorized file system access due to path traversal and missing storage path validation Exploitation status Not known exploited Fix YesPublished 09/10/2026 Severity Medium CVE-2026-14470Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base components Exploitation status Not known exploited Fix YesPublished 09/04/2026 Severity Medium CVE-2026-17627Langflow is affected by improper authorization due to missing access control on the voice-mode WebSocket endpoint Exploitation status Not known exploited Fix YesPublished 09/04/2026 Severity Medium CVE-2026-17621Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base components Exploitation status Not known exploited Fix YesPublished 09/04/2026 Severity Medium CVE-2026-17622Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base components Exploitation status Not known exploited Fix YesPublished 09/04/2026 Severity Medium CVE-2026-17631Langflow OSS is affected by server-side request forgery due to missing URL validation in flow components Exploitation status Not known exploited Fix YesPublished 09/04/2026 Severity Medium CVE-2026-19298Langflow is vulnerable to remote code execution due to authorization policy bypass in the authenticated flow-build endpoint Exploitation status Not known exploited Fix YesPublished 09/04/2026 Severity High CVE-2026-19301Langflow is vulnerable to Server-Side Request Forgery due to missing or bypassable URL validation in multiple components Exploitation status Not known exploited Fix YesPublished 09/04/2026 Severity Medium CVE-2026-19303Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing components Exploitation status Not known exploited Fix YesPublished 09/04/2026 Severity High CVE-2026-19300Langflow is vulnerable to information disclosure due to cross-user MCP tool cache collision and incomplete secret scrubbing on public flows Exploitation status Not known exploited Fix YesPublished 09/04/2026 Severity High CVE-2026-19299Langflow is vulnerable to arbitrary local file read due to path traversal in ChatInput, bundle FileInput, and GitExtractor components Exploitation status Not known exploited Fix YesPublished 09/04/2026 Severity Medium CVE-2026-19302Langflow is vulnerable to arbitrary local file read due to path traversal in ChatInput, bundle FileInput, and GitExtractor components Exploitation status Not known exploited Fix YesPublished 09/04/2026 Severity Medium CVE-2026-19304Langflow is vulnerable to Server-Side Request Forgery due to missing or bypassable URL validation in multiple components Exploitation status Not known exploited Fix YesPublished 09/04/2026 Severity High CVE-2026-19305Langflow is vulnerable to Server-Side Request Forgery due to missing or bypassable URL validation in multiple components Exploitation status Not known exploited Fix YesPublished 09/04/2026 Severity High CVE-2026-19306Langflow is vulnerable to arbitrary local file read due to path traversal in ChatInput, bundle FileInput, and GitExtractor components Exploitation status Not known exploited Fix YesPublished 09/04/2026 Severity High CVE-2026-9138Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing components Exploitation status Not known exploited Fix YesPublished 09/04/2026 Severity Medium CVE-2026-8447Langflow is vulnerable to stored cross-site scripting and IP spoofing due to unsanitized Markdown rendering and untrusted proxy header trust Exploitation status Not known exploited Fix YesPublished 09/04/2026 Severity Medium CVE-2026-9186Langflow is vulnerable to stored cross-site scripting and IP spoofing due to unsanitized Markdown rendering and untrusted proxy header trust Exploitation status Not known exploited Fix YesPublished 09/04/2026 Severity Medium CVE-2026-19295Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement Exploitation status Not known exploited Fix YesPublished 08/28/2026 Severity Critical CVE-2026-19294Langflow is affected by multiple authentication bypass, path traversal, authorization, and server-side request forgery vulnerabilities Exploitation status Not known exploited Fix YesPublished 08/28/2026 Severity Medium CVE-2026-19286Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement Exploitation status Not known exploited Fix YesPublished 08/28/2026 Severity Critical CVE-2026-18904Langflow is affected by multiple authentication bypass, path traversal, authorization, and server-side request forgery vulnerabilities Exploitation status Not known exploited Fix YesPublished 08/28/2026 Severity High CVE-2026-18899Langflow is affected by multiple authentication bypass, path traversal, authorization, and server-side request forgery vulnerabilities Exploitation status Not known exploited Fix YesPublished 08/28/2026 Severity High CVE-2026-18891Langflow is affected by multiple authentication bypass, path traversal, authorization, and server-side request forgery vulnerabilities Exploitation status Not known exploited Fix YesPublished 08/28/2026 Severity High CVE-2026-18729Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement Exploitation status Not known exploited Fix YesPublished 08/28/2026 Severity High CVE-2026-18545Langflow is affected by multiple authentication bypass, path traversal, authorization, and server-side request forgery vulnerabilities Exploitation status Not known exploited Fix YesPublished 08/28/2026 Severity Medium CVE-2026-19875Unauthenticated Registration POST Endpoint Permits Admin Email Overwrite and Outbound Relay Abuse in Langflow Exploitation status Not known exploited Fix YesPublished 08/19/2026 Severity High CVE-2026-19297Insufficient Authentication Brute Force Protection on Login Endpoint Exploitation status Not known exploited Fix YesPublished 08/13/2026 Severity Critical CVE-2026-17624Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling Exploitation status Not known exploited Fix YesPublished 08/05/2026 Severity High CVE-2026-17633Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling Exploitation status Not known exploited Fix YesPublished 08/05/2026 Severity High CVE-2026-17632Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling Exploitation status Not known exploited Fix YesPublished 08/05/2026 Severity High CVE-2026-9196Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling Exploitation status Not known exploited Fix YesPublished 08/05/2026 Severity High CVE-2026-8182Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling Exploitation status Not known exploited Fix YesPublished 08/05/2026 Severity High CVE-2026-9201Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling Exploitation status Not known exploited Fix YesPublished 08/05/2026 Severity High CVE-2026-8478Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling Exploitation status Not known exploited Fix YesPublished 08/05/2026 Severity High CVE-2026-8183Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement Exploitation status Not known exploited Fix YesPublished 08/05/2026 Severity High CVE-2026-7658Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement Exploitation status Not known exploited Fix YesPublished 08/05/2026 Severity Medium CVE-2026-9130Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement Exploitation status Not known exploited Fix YesPublished 08/05/2026 Severity High CVE-2026-10547Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement Exploitation status Not known exploited Fix YesPublished 08/05/2026 Severity Medium CVE-2026-7869Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement Exploitation status Not known exploited Fix YesPublished 08/05/2026 Severity Medium CVE-2026-8470Langflow is affected by weaknesses in secret handling and sensitive configuration access Exploitation status Not known exploited Fix YesPublished 08/05/2026 Severity High CVE-2026-9205Langflow is affected by weaknesses in secret handling and sensitive configuration access Exploitation status Not known exploited Fix YesPublished 08/05/2026 Severity High CVE-2026-10128Langflow is affected by weaknesses in secret handling and sensitive configuration access Exploitation status Not known exploited Fix YesPublished 08/05/2026 Severity Medium CVE-2026-9081Langflow OSS is affected by server-side request forgery in provider validation and API request functionality Exploitation status Not known exploited Fix YesPublished 08/05/2026 Severity High CVE-2026-7657Langflow OSS is affected by server-side request forgery in provider validation and API request functionality Exploitation status Not known exploited Fix YesPublished 08/05/2026 Severity Medium CVE-2026-17625Langflow is affected by OS Command Injection in Model Context Protocol features Exploitation status Not known exploited Fix YesPublished 08/05/2026 Severity High CVE-2026-17623Langflow is affected OS Command Injection in Model Context Protocol features Exploitation status Not known exploited Fix YesPublished 08/05/2026 Severity High CVE-2026-17630Langflow is affected by security vulnerabilities in Model Context Protocol features Exploitation status Not known exploited Fix YesPublished 08/05/2026 Severity High CVE-2026-17626Langflow is affected by security vulnerabilities in Model Context Protocol features Exploitation status Not known exploited Fix YesPublished 08/05/2026 Severity High CVE-2026-8446Langflow is affected by security vulnerabilities in Model Context Protocol features Exploitation status Not known exploited Fix YesPublished 08/05/2026 Severity High CVE-2026-7646Langflow is affected by security vulnerabilities in Model Context Protocol features Exploitation status Not known exploited Fix YesPublished 08/05/2026 Severity Medium CVE-2026-9077Reliance on Untrusted Inputs in a Security Decision vulnerabilities in Model Context Protocol features Exploitation status Not known exploited Fix YesPublished 08/05/2026 Severity High CVE-2026-12946Remote Code Execution in CUGA Component CodeAgent Exploitation status Not known exploited Fix YesPublished 07/30/2026 Severity Critical CVE-2026-13444Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints Exploitation status Not known exploited Fix YesPublished 07/30/2026 Severity High CVE-2026-10700Broken Access Control Vulnerabilities in Langflow 1.0.0 - 1.8.4 File Handling API Allowed Unauthorized Access to User Files Exploitation status Not known exploited Fix YesPublished 07/30/2026 Severity Medium CVE-2026-13435Python Interpreter Sandbox Bypass Leading to Sensitive Data Exposure Exploitation status Not known exploited Fix YesPublished 07/30/2026 Severity Critical CVE-2026-12942Langflow is affected by path traversal due to multiple unauthenticated and insufficiently authorized API endpoints Exploitation status Not known exploited Fix YesPublished 07/30/2026 Severity High CVE-2026-12945Langflow is affected by exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints Exploitation status Not known exploited Fix YesPublished 07/30/2026 Severity High CVE-2026-12940Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpoints Exploitation status Not known exploited Fix YesPublished 07/30/2026 Severity Critical CVE-2026-13442Langflow is affected by NET Misconfiguration: Use of Impersonation due to multiple unauthenticated and insufficiently authorized API endpoints Exploitation status Not known exploited Fix YesPublished 07/28/2026 Severity High CVE-2026-13445Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints Exploitation status Not known exploited Fix YesPublished 07/17/2026 Severity High CVE-2026-13446Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints Exploitation status Not known exploited Fix YesPublished 07/17/2026 Severity Critical CVE-2026-13448Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints Exploitation status Not known exploited Fix YesPublished 07/17/2026 Severity High CVE-2026-14499Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints Exploitation status Not known exploited Fix YesPublished 07/17/2026 Severity High CVE-2026-7667Path Traversal Vulnerability in API Request Component Content-Disposition Header Processing Exploitation status Not known exploited Fix YesPublished 07/17/2026 Severity High CVE-2026-7754SSRF Protection Configuration Vulnerability Exploitation status Not known exploited Fix YesPublished 07/17/2026 Severity High CVE-2026-7755MCP Server Configuration Validator Bypass via File Upload API Exploitation status Not known exploited Fix YesPublished 07/17/2026 Severity High CVE-2026-7872Path Traversal Vulnerability in File Component Leading to Arbitrary File Read and Authentication Bypass Exploitation status Not known exploited Fix YesPublished 07/17/2026 Severity High CVE-2026-8056Parameter Injection Vulnerability in API Graph Execution Engine Exploitation status Not known exploited Fix YesPublished 07/17/2026 Severity High CVE-2026-8476Disk Cache Deserialization Remote Code Execution Vulnerability Exploitation status Not known exploited Fix YesPublished 07/17/2026 Severity Critical CVE-2026-8481Remote Code Execution via Code Validation Endpoint Exploitation status Not known exploited Fix YesPublished 07/17/2026 Severity Critical CVE-2026-8505Authentication Bypass in Webhook Endpoints Allowed Unauthorized Flow Execution Exploitation status Not known exploited Fix YesPublished 07/17/2026 Severity Critical CVE-2026-8635Arbitrary Code Execution in Python Interpreter Component Exploitation status Not known exploited Fix YesPublished 07/17/2026 Severity Critical CVE-2026-8859Path Traversal in APIRequest Component via Content-Disposition Header Exploitation status Not known exploited Fix YesPublished 07/17/2026 Severity Critical CVE-2026-9103Unauthenticated Superuser Token Issuance via Auto-Login Endpoint Exploitation status Not known exploited Fix YesPublished 07/17/2026 Severity Critical CVE-2026-9135Policies Component Dynamic CodeInput Fields Bypass Custom Component Validation Exploitation status Not known exploited Fix YesPublished 07/17/2026 Severity Critical CVE-2026-9198Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation Exploitation status KEV Fix YesPublished 07/17/2026 Severity Critical CVE-2026-9202Unauthenticated User Registration Could Lead to Remote Code Execution Exploitation status Not known exploited Fix YesPublished 07/17/2026 Severity Critical CVE-2026-10129SSRF via HTTP Redirect Following in Langflow API Request Component Exploitation status Not known exploited Fix YesPublished 06/30/2026 Severity High CVE-2026-10134Unauthenticated Server-Side RCE via PythonCodeStructuredTool in Public Flows Exploitation status Not known exploited Fix YesPublished 06/30/2026 Severity Critical CVE-2026-10140Cross-Tenant API Key Reuse and Billing Fraud in Langflow Voice Mode Subsystem Exploitation status Not known exploited Fix YesPublished 06/30/2026 Severity Critical CVE-2026-10546DNS Rebinding TOCTOU Bypass of SSRF Protection in Langflow OSS URL Component Exploitation status Not known exploited Fix YesPublished 06/30/2026 Severity High CVE-2026-10560Unauthenticated Access to Private Flow Build Events and Cancellation in Langflow OSS Exploitation status Not known exploited Fix YesPublished 06/30/2026 Severity High