Langflow

Langflow-AI · 42 CVEs

CVE-2026-105741
HIGH

Langflow: IP Spoofing Bypass via `X-Forwarded-For` Allowing Remote Configuration Write

Oct 5, 2026

CVE-2026-105740
CRITICAL

Langflow: Authenticated RCE via MCP Stdio transport allows any user to execute arbitrary OS commands on the server

Oct 5, 2026

CVE-2026-105699
HIGH

Langflow: Authenticated Cross-Project File Disclosure via Unscoped MCP Resource Handlers

Oct 5, 2026

CVE-2026-105698
MEDIUM

Langflow: Cross-user flow access and vertex execution via deprecated /api/v1/build/{flow_id}/vertices endpoints

Oct 5, 2026

CVE-2026-105697
CRITICAL

Langflow: OS command injection (RCE) via arbitrary command in MCP stdio server configuration

Oct 5, 2026

CVE-2026-101861
LOW

Langflow Code Execution via eval() in Component Input Schema

Sep 28, 2026

CVE-2026-48520
MEDIUM

Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read

Jun 23, 2026

CVE-2026-33760
HIGH

Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints

Jun 23, 2026

CVE-2026-42867
MEDIUM

Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint

Jun 23, 2026

CVE-2026-55255
KEV HIGH

Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Fl…

Jun 23, 2026

CVE-2026-55423
MEDIUM

Langflow: Logout button does not clear session

Jun 23, 2026

CVE-2026-55446
HIGH

Langflow: Unauthenticated DoS through multipart form boundary file upload

Jun 23, 2026

CVE-2026-48519
CRITICAL

Langflow: Unauthenticated RCE in Shareable Playgrounds

Jun 23, 2026

CVE-2026-55447
CRITICAL

Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit

Jun 23, 2026

CVE-2026-55450
CRITICAL

Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak

Jun 23, 2026

CVE-2026-12822
MEDIUM

langflow-ai langflow Bundle URL Loader code injection

Jun 21, 2026

CVE-2026-42048
CRITICAL

Langflow: Path Traversal in Langflow Knowledge Bases API

May 12, 2026

CVE-2026-7700
MEDIUM

langflow-ai langflow LambdaFilterComponent lambda_filter.py eval code injection

May 3, 2026

CVE-2026-7687
MEDIUM

langflow-ai langflow Full Builtins code_parser.py CodeParser.parse_callable_details command injection

May 3, 2026

CVE-2026-6600
MEDIUM

langflow-ai langflow Frontend React Component Rendering edit-message.tsx cross site scripting

Apr 20, 2026

CVE-2026-6599
MEDIUM

langflow-ai langflow Model Context Protocol Configuration API mcp_projects.py install_mcp_config injection

Apr 20, 2026

CVE-2026-6598
MEDIUM

langflow-ai langflow Project Creation Endpoint projects.py encrypt_auth_settings cleartext storage in file

Apr 20, 2026

CVE-2026-6597
MEDIUM

langflow-ai langflow Flow Using API core.py has_api_terms credentials storage

Apr 20, 2026

CVE-2026-6596
MEDIUM

langflow-ai langflow API Endpoint endpoints.py create_upload_file unrestricted upload

Apr 20, 2026

CVE-2026-34046
HIGH

Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check

Mar 27, 2026

Showing 1 to 25 of 42 CVEs