← Browse

Langflow

41 CVEs
CVE IDSeverityProduct / summaryPublished
CVE-2026-13445 HIGH 8.1 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component … 2026-07-17 CVE-2026-13446 CRITICAL 9.8 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key… 2026-07-17 CVE-2026-13448 HIGH 8.1 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerabil… 2026-07-17 CVE-2026-14499 HIGH 8.8 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands… 2026-07-17 CVE-2026-7667 HIGH 8.8 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to … 2026-07-17 CVE-2026-7754 HIGH 7.7 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to ins… 2026-07-17 CVE-2026-7755 HIGH 8.8 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation … 2026-07-17 CVE-2026-7872 HIGH 7.5 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the J… 2026-07-17 CVE-2026-8056 HIGH 8.8 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime v… 2026-07-17 CVE-2026-8476 CRITICAL 9.9 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based… 2026-07-17 CVE-2026-8481 CRITICAL 9.9 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code valid… 2026-07-17 CVE-2026-8505 CRITICAL 9.8 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows un… 2026-07-17 CVE-2026-8635 CRITICAL 9.9 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by direct… 2026-07-17 CVE-2026-8859 CRITICAL 9.9 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended … 2026-07-17 CVE-2026-9103 CRITICAL 9.8 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to imprope… 2026-07-17 CVE-2026-9135 CRITICAL 9.9 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc… 2026-07-17 CVE-2026-10129 HIGH 8.5 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) protection bypass vulnerabi… 2026-06-30 CVE-2026-10134 CRITICAL 10 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process… 2026-06-30 CVE-2026-10140 CRITICAL 9.6 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of … 2026-06-30 CVE-2026-10546 HIGH 7.1 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the URL co… 2026-06-30 CVE-2026-10560 HIGH 8.2 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_t… 2026-06-30 CVE-2026-10564 HIGH 8.2 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.9.6 contains a Server-Side Request Forgery (SSRF). The legacy RSSReaderCompon… 2026-06-30 CVE-2026-7663 CRITICAL 9.1 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project res… 2026-06-30 CVE-2026-7803 CRITICAL 9.8 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validation of flow … 2026-06-30 CVE-2026-7871 CRITICAL 9.8 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full appli… 2026-06-30 CVE-2026-7873 CRITICAL 9.9 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read… 2026-06-30 CVE-2026-7874 CRITICAL 9.1 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored credentials due to the use… 2026-06-30 CVE-2026-33760 HIGH 8.8 Langflow — Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow's /api… 2026-06-23 CVE-2026-42867 MEDIUM 6.5 Langflow — Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vul…● PoC 2026-06-23 CVE-2026-48519 CRITICAL 9.6 Langflow — Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, the "Shareable …● PoC 2026-06-23 CVE-2026-48520 MEDIUM 6.1 Langflow — Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.10.0, the "Shareable…● PoC 2026-06-23 CVE-2026-55255 HIGH 8.4 Langflow — Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Dir…● exploited 2026-06-23 CVE-2026-55423 MEDIUM 6.1 Langflow — Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.7.0, the logout butt… 2026-06-23 CVE-2026-55446 HIGH 7.5 Langflow — Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.0.19, an attacker ca…● PoC 2026-06-23 CVE-2026-55447 CRITICAL 9.6 Langflow — Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling … 2026-06-23 CVE-2026-55450 CRITICAL 9.3 Langflow — Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated…● PoC 2026-06-23 CVE-2026-10561 CRITICAL 10 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution com… 2026-06-22 CVE-2026-7664 CRITICAL 9.8 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project res… 2026-06-22 CVE-2026-12822 MEDIUM 4.8 Langflow — A vulnerability was identified in langflow-ai langflow up to 1.9.3. This affects an unknown function of the co…● PoC 2026-06-21 CVE-2026-3341 MEDIUM 5.4 Langflow Desktop — IBM Langflow Desktop 1.0.0 through 1.9.2 IBM Langflow is vulnerable to server-side request forgery (SSRF). Thi… 2026-06-11 CVE-2026-7787 HIGH 7.5 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information… 2026-06-11