Langflow
Langflow-AI · 42 CVEs
Langflow: IP Spoofing Bypass via `X-Forwarded-For` Allowing Remote Configuration Write
Oct 5, 2026
Langflow: Authenticated RCE via MCP Stdio transport allows any user to execute arbitrary OS commands on the server
Oct 5, 2026
Langflow: Authenticated Cross-Project File Disclosure via Unscoped MCP Resource Handlers
Oct 5, 2026
Langflow: Cross-user flow access and vertex execution via deprecated /api/v1/build/{flow_id}/vertices endpoints
Oct 5, 2026
Langflow: OS command injection (RCE) via arbitrary command in MCP stdio server configuration
Oct 5, 2026
Langflow Code Execution via eval() in Component Input Schema
Sep 28, 2026
Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read
Jun 23, 2026
Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints
Jun 23, 2026
Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint
Jun 23, 2026
Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Fl…
Jun 23, 2026
Langflow: Logout button does not clear session
Jun 23, 2026
Langflow: Unauthenticated DoS through multipart form boundary file upload
Jun 23, 2026
Langflow: Unauthenticated RCE in Shareable Playgrounds
Jun 23, 2026
Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
Jun 23, 2026
Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
Jun 23, 2026
langflow-ai langflow Bundle URL Loader code injection
Jun 21, 2026
Langflow: Path Traversal in Langflow Knowledge Bases API
May 12, 2026
langflow-ai langflow LambdaFilterComponent lambda_filter.py eval code injection
May 3, 2026
langflow-ai langflow Full Builtins code_parser.py CodeParser.parse_callable_details command injection
May 3, 2026
langflow-ai langflow Frontend React Component Rendering edit-message.tsx cross site scripting
Apr 20, 2026
langflow-ai langflow Model Context Protocol Configuration API mcp_projects.py install_mcp_config injection
Apr 20, 2026
langflow-ai langflow Project Creation Endpoint projects.py encrypt_auth_settings cleartext storage in file
Apr 20, 2026
langflow-ai langflow Flow Using API core.py has_api_terms credentials storage
Apr 20, 2026
langflow-ai langflow API Endpoint endpoints.py create_upload_file unrestricted upload
Apr 20, 2026
Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check
Mar 27, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-105741 | Langflow: IP Spoofing Bypass via `X-Forwarded-For` Allowing Remote Configuration Write | HIGH | n/a | Oct 5, 2026 |
| CVE-2026-105740 | Langflow: Authenticated RCE via MCP Stdio transport allows any user to execute arbitrary OS commands on the server | CRITICAL | n/a | Oct 5, 2026 |
| CVE-2026-105699 | Langflow: Authenticated Cross-Project File Disclosure via Unscoped MCP Resource Handlers | HIGH | n/a | Oct 5, 2026 |
| CVE-2026-105698 | Langflow: Cross-user flow access and vertex execution via deprecated /api/v1/build/{flow_id}/vertices endpoints | MEDIUM | n/a | Oct 5, 2026 |
| CVE-2026-105697 | Langflow: OS command injection (RCE) via arbitrary command in MCP stdio server configuration | CRITICAL | n/a | Oct 5, 2026 |
| CVE-2026-101861 | Langflow Code Execution via eval() in Component Input Schema | LOW | 0.20% | Sep 28, 2026 |
| CVE-2026-48520 | Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read | MEDIUM | 0.44% | Jun 23, 2026 |
| CVE-2026-33760 | Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints | HIGH | 0.50% | Jun 23, 2026 |
| CVE-2026-42867 | Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint | MEDIUM | 0.47% | Jun 23, 2026 |
| CVE-2026-55255 KEV | Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow | HIGH | 0.89% | Jun 23, 2026 |
| CVE-2026-55423 | Langflow: Logout button does not clear session | MEDIUM | 0.22% | Jun 23, 2026 |
| CVE-2026-55446 | Langflow: Unauthenticated DoS through multipart form boundary file upload | HIGH | 0.58% | Jun 23, 2026 |
| CVE-2026-48519 | Langflow: Unauthenticated RCE in Shareable Playgrounds | CRITICAL | 0.78% | Jun 23, 2026 |
| CVE-2026-55447 | Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit | CRITICAL | 0.66% | Jun 23, 2026 |
| CVE-2026-55450 | Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak | CRITICAL | 1.19% | Jun 23, 2026 |
| CVE-2026-12822 | langflow-ai langflow Bundle URL Loader code injection | MEDIUM | 0.28% | Jun 21, 2026 |
| CVE-2026-42048 | Langflow: Path Traversal in Langflow Knowledge Bases API | CRITICAL | 0.60% | May 12, 2026 |
| CVE-2026-7700 | langflow-ai langflow LambdaFilterComponent lambda_filter.py eval code injection | MEDIUM | 0.39% | May 3, 2026 |
| CVE-2026-7687 | langflow-ai langflow Full Builtins code_parser.py CodeParser.parse_callable_details command injection | MEDIUM | 2.60% | May 3, 2026 |
| CVE-2026-6600 | langflow-ai langflow Frontend React Component Rendering edit-message.tsx cross site scripting | MEDIUM | 0.33% | Apr 20, 2026 |
| CVE-2026-6599 | langflow-ai langflow Model Context Protocol Configuration API mcp_projects.py install_mcp_config injection | MEDIUM | 0.39% | Apr 20, 2026 |
| CVE-2026-6598 | langflow-ai langflow Project Creation Endpoint projects.py encrypt_auth_settings cleartext storage in file | MEDIUM | 0.24% | Apr 20, 2026 |
| CVE-2026-6597 | langflow-ai langflow Flow Using API core.py has_api_terms credentials storage | MEDIUM | 0.38% | Apr 20, 2026 |
| CVE-2026-6596 | langflow-ai langflow API Endpoint endpoints.py create_upload_file unrestricted upload | MEDIUM | 0.47% | Apr 20, 2026 |
| CVE-2026-34046 | Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check | HIGH | 0.68% | Mar 27, 2026 |
Showing 1 to 25 of 42 CVEs