Langflow
42 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-18545
MEDIUM 4.3
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.11.1 is vulnerable to server-side request forgery (SSRF). This may allow an a…
2026-08-28
CVE-2026-18729
HIGH 8.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code du…
2026-08-28
CVE-2026-18891
HIGH 8.2
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sens…
2026-08-28
CVE-2026-18899
HIGH 7.5
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbitrary files due to path traver…
2026-08-28
CVE-2026-18904
HIGH 8.2
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject…
2026-08-28
CVE-2026-19286
CRITICAL 9.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper …
2026-08-28
CVE-2026-19294
MEDIUM 6.4
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute and read any user…
2026-08-28
CVE-2026-19295
CRITICAL 9.9
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system c…
2026-08-28
CVE-2026-19875
HIGH 7.5
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email informati…
2026-08-19
CVE-2026-19297
CRITICAL 9.1
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accou…
2026-08-13
CVE-2026-10128
MEDIUM 6.5
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to …
2026-08-05
CVE-2026-10547
MEDIUM 5.9
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/buil…
2026-08-05
CVE-2026-17623
HIGH 8.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary command…
2026-08-05
CVE-2026-17624
HIGH 8.5
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0…
2026-08-05
CVE-2026-17625
HIGH 7.2
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0…
2026-08-05
CVE-2026-17626
HIGH 8.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expos…
2026-08-05
CVE-2026-17630
HIGH 7.2
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper …
2026-08-05
CVE-2026-17632
HIGH 8.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code du…
2026-08-05
CVE-2026-17633
HIGH 8.5
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code du…
2026-08-05
CVE-2026-7646
MEDIUM 6.5
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, includi…
2026-08-05
CVE-2026-7657
MEDIUM 6.5
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplet…
2026-08-05
CVE-2026-7658
MEDIUM 6.5
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inj…
2026-08-05
CVE-2026-7869
MEDIUM 5.4
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v…
2026-08-05
CVE-2026-8182
HIGH 8.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on …
2026-08-05
CVE-2026-8183
HIGH 7.7
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0…
2026-08-05
CVE-2026-8446
HIGH 7.5
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Prot…
2026-08-05
CVE-2026-8470
HIGH 7.4
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 us…
2026-08-05
CVE-2026-8478
HIGH 8.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, du…
2026-08-05
CVE-2026-9077
HIGH 8.5
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only …
2026-08-05
CVE-2026-9081
HIGH 7.1
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) …
2026-08-05
CVE-2026-9130
HIGH 7.1
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent tha…
2026-08-05
CVE-2026-9196
HIGH 8.1
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during …
2026-08-05
CVE-2026-9201
HIGH 8.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a…
2026-08-05
CVE-2026-9205
HIGH 7.4
Langflow Oss — IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() functio…
2026-08-05
CVE-2026-10700
MEDIUM 6.5
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handl…
2026-07-30
CVE-2026-12940
CRITICAL 9.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment…
2026-07-30
CVE-2026-12942
HIGH 7.5
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An …
2026-07-30
CVE-2026-12945
HIGH 7.1
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build j…
2026-07-30
CVE-2026-12946
CRITICAL 9.9
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, du…
2026-07-30
CVE-2026-13435
CRITICAL 9.9
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sa…
2026-07-30
CVE-2026-13444
HIGH 8.1
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents …
2026-07-30
CVE-2026-13442
HIGH 7.1
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access …
2026-07-28