langflow-ai
- Products in analyzed data
- 2
- Catalog vulnerabilities
- 36
Severity across 36 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 36 analyzed records
A short verification protects source data and prevents automated AI requests.
As of 09/11/2026, langflow-ai recorded 10 security vulnerabilities in the last 90 days across 1 products, including 6 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, langflow had the most security vulnerabilities in the langflow-ai ecosystem, with 10 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
| CVE | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-48520Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read | Exploitation statusPublic exploit | FixYes | Affected productlangflow | Published06/23/2026 | SeverityMedium |
CVE-2026-33760Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints | Exploitation statusPublic exploit | FixYes | Affected productlangflow | Published06/23/2026 | SeverityHigh |
CVE-2026-42867Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint | Exploitation statusPublic exploit | FixYes | Affected productlangflow | Published06/23/2026 | SeverityMedium |
CVE-2026-55255Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow | Exploitation statusPublic exploit | FixYes | Affected productlangflow | Published06/23/2026 | SeverityHigh |
CVE-2026-55423Langflow: Logout button does not clear session | Exploitation statusPublic exploit | FixYes | Affected productlangflow | Published06/23/2026 | SeverityMedium |
CVE-2026-55446Langflow: Unauthenticated DoS through multipart form boundary file upload | Exploitation statusPublic exploit | FixYes | Affected productlangflow | Published06/23/2026 | SeverityHigh |
CVE-2026-48519Langflow: Unauthenticated RCE in Shareable Playgrounds | Exploitation statusPublic exploit | FixYes | Affected productlangflow | Published06/23/2026 | SeverityCritical |
CVE-2026-55447Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit | Exploitation statusNot known exploited | FixYes | Affected productlangflow | Published06/23/2026 | SeverityCritical |
CVE-2026-55450Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak | Exploitation statusPublic exploit | FixYes | Affected productlangflow | Published06/23/2026 | SeverityCritical |
CVE-2026-12822langflow-ai langflow Bundle URL Loader code injection | Exploitation statusPublic exploit | FixNot confirmed | Affected productlangflow | Published06/21/2026 | SeverityMedium |
CVE-2026-42048Langflow: Path Traversal in Langflow Knowledge Bases API | Exploitation statusPublic exploit | FixYes | Affected productlangflow | Published05/12/2026 | SeverityCritical |
CVE-2026-7700langflow-ai langflow LambdaFilterComponent lambda_filter.p eval code injection | Exploitation statusPublic exploit | FixNot confirmed | Affected productlangflow | Published05/03/2026 | SeverityMedium |
CVE-2026-7687langflow-ai langflow Full Builtins code_parser.py CodeParser.parse_callable_details command injection | Exploitation statusPublic exploit | FixNot confirmed | Affected productlangflow | Published05/03/2026 | SeverityMedium |
CVE-2026-6600langflow-ai langflow Frontend React Component Rendering edit-message.tsx cross site scripting | Exploitation statusPublic exploit | FixNot confirmed | Affected productlangflow | Published04/20/2026 | SeverityMedium |
CVE-2026-6599langflow-ai langflow Model Context Protocol Configuration API mcp_projects.py install_mcp_config injection | Exploitation statusPublic exploit | FixNot confirmed | Affected productlangflow | Published04/20/2026 | SeverityMedium |
CVE-2026-6598langflow-ai langflow Project Creation Endpoint projects.py encrypt_auth_settings cleartext storage in file | Exploitation statusPublic exploit | FixNot confirmed | Affected productlangflow | Published04/20/2026 | SeverityMedium |
CVE-2026-6597langflow-ai langflow Flow Using API core.py has_api_terms credentials storage | Exploitation statusPublic exploit | FixNot confirmed | Affected productlangflow | Published04/20/2026 | SeverityMedium |
CVE-2026-6596langflow-ai langflow API Endpoint endpoints.py create_upload_file unrestricted upload | Exploitation statusPublic exploit | FixNot confirmed | Affected productlangflow | Published04/20/2026 | SeverityMedium |
CVE-2026-34046Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check | Exploitation statusNot known exploited | FixNot confirmed | Affected productlangflow | Published03/27/2026 | SeverityHigh |
CVE-2026-33873Langflow has Authenticated Code Execution in Agentic Assistant Validation | Exploitation statusNot known exploited | FixNot confirmed | Affected productlangflow | Published03/27/2026 | SeverityCritical |
CVE-2026-5027Langflow - Path Traversal Arbitrary File Write via upload_user_file | Exploitation statusNot known exploited | FixNot confirmed | Affected productlangflow | Published03/27/2026 | SeverityHigh |
CVE-2026-5026Langflow - Stored XSS via Malicious SVG Upload | Exploitation statusNot known exploited | FixNot confirmed | Affected productlangflow | Published03/27/2026 | SeverityHigh |
CVE-2026-5025Langflow - Application Logs Exposed to All Authenticated Users | Exploitation statusNot known exploited | FixNot confirmed | Affected productlangflow | Published03/27/2026 | SeverityMedium |
CVE-2026-5022Langflow - Missing Authorization on download_image Endpoint | Exploitation statusNot known exploited | FixNot confirmed | Affected productlangflow | Published03/27/2026 | SeverityMedium |
CVE-2026-33497Langflow: /profile_pictures/{folder_name}/{file_name} endpoint file reading | Exploitation statusPublic exploit | FixNot confirmed | Affected productlangflow | Published03/24/2026 | SeverityHigh |
CVE-2026-33484Langflow has Unauthenticated IDOR on Image Downloads | Exploitation statusPublic exploit | FixNot confirmed | Affected productlangflow | Published03/24/2026 | SeverityHigh |
CVE-2026-33475Langflow GitHub Actions Shell Injection | Exploitation statusPublic exploit | FixNot confirmed | Affected productlangflow | Published03/24/2026 | SeverityCritical |
CVE-2026-33309Langflow has an Arbitrary File Write (RCE) via v2 API | Exploitation statusPublic exploit | FixNot confirmed | Affected productlangflow | Published03/24/2026 | SeverityCritical |
CVE-2026-33053Langflow has Missing Ownership Verification in API Key Deletion (IDOR) | Exploitation statusNot known exploited | FixNot confirmed | Affected productlangflow | Published03/20/2026 | SeverityMedium |
CVE-2026-33017Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint | Exploitation statusKEV | FixYes | Affected productlangflow | Published03/20/2026 | SeverityCritical |
CVE-2026-27966Langflow has Remote Code Execution in CSV Agent | Exploitation statusPublic exploit | FixNot confirmed | Affected productlangflow | Published02/26/2026 | SeverityCritical |
CVE-2026-21445Langflow Missing Authentication on Critical API Endpoints | Exploitation statusNot known exploited | FixNot confirmed | Affected productlangflow | Published01/02/2026 | SeverityHigh |
CVE-2025-68478Langflow Vulnerable to External Control of File Name or Path | Exploitation statusPublic exploit | FixNot confirmed | Affected productlangflow | Published12/19/2025 | SeverityHigh |
CVE-2025-68477Langflow vulnerable to Server-Side Request Forgery | Exploitation statusPublic exploit | FixNot confirmed | Affected productlangflow | Published12/19/2025 | SeverityHigh |
CVE-2025-57760Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation | Exploitation statusPublic exploit | FixNot confirmed | Affected productlangflow | Published08/25/2025 | SeverityHigh |
CVE-2025-3248Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code | Exploitation statusKEV | FixYes | Affected productlangflow | Published04/07/2025 | SeverityCritical |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan