Langflow
41 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-13445
HIGH 8.1
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component …
2026-07-17
CVE-2026-13446
CRITICAL 9.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key…
2026-07-17
CVE-2026-13448
HIGH 8.1
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerabil…
2026-07-17
CVE-2026-14499
HIGH 8.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands…
2026-07-17
CVE-2026-7667
HIGH 8.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to …
2026-07-17
CVE-2026-7754
HIGH 7.7
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to ins…
2026-07-17
CVE-2026-7755
HIGH 8.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation …
2026-07-17
CVE-2026-7872
HIGH 7.5
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the J…
2026-07-17
CVE-2026-8056
HIGH 8.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime v…
2026-07-17
CVE-2026-8476
CRITICAL 9.9
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based…
2026-07-17
CVE-2026-8481
CRITICAL 9.9
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code valid…
2026-07-17
CVE-2026-8505
CRITICAL 9.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows un…
2026-07-17
CVE-2026-8635
CRITICAL 9.9
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by direct…
2026-07-17
CVE-2026-8859
CRITICAL 9.9
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended …
2026-07-17
CVE-2026-9103
CRITICAL 9.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to imprope…
2026-07-17
CVE-2026-9135
CRITICAL 9.9
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc…
2026-07-17
CVE-2026-10129
HIGH 8.5
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) protection bypass vulnerabi…
2026-06-30
CVE-2026-10134
CRITICAL 10
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process…
2026-06-30
CVE-2026-10140
CRITICAL 9.6
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of …
2026-06-30
CVE-2026-10546
HIGH 7.1
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the URL co…
2026-06-30
CVE-2026-10560
HIGH 8.2
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_t…
2026-06-30
CVE-2026-10564
HIGH 8.2
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.9.6 contains a Server-Side Request Forgery (SSRF). The legacy RSSReaderCompon…
2026-06-30
CVE-2026-7663
CRITICAL 9.1
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project res…
2026-06-30
CVE-2026-7803
CRITICAL 9.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validation of flow …
2026-06-30
CVE-2026-7871
CRITICAL 9.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full appli…
2026-06-30
CVE-2026-7873
CRITICAL 9.9
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read…
2026-06-30
CVE-2026-7874
CRITICAL 9.1
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored credentials due to the use…
2026-06-30
CVE-2026-33760
HIGH 8.8
Langflow — Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow's /api…
2026-06-23
CVE-2026-42867
MEDIUM 6.5
Langflow — Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vul…● PoC
2026-06-23
CVE-2026-48519
CRITICAL 9.6
Langflow — Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, the "Shareable …● PoC
2026-06-23
CVE-2026-48520
MEDIUM 6.1
Langflow — Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.10.0, the "Shareable…● PoC
2026-06-23
CVE-2026-55255
HIGH 8.4
Langflow — Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Dir…● exploited
2026-06-23
CVE-2026-55423
MEDIUM 6.1
Langflow — Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.7.0, the logout butt…
2026-06-23
CVE-2026-55446
HIGH 7.5
Langflow — Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.0.19, an attacker ca…● PoC
2026-06-23
CVE-2026-55447
CRITICAL 9.6
Langflow — Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling …
2026-06-23
CVE-2026-55450
CRITICAL 9.3
Langflow — Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated…● PoC
2026-06-23
CVE-2026-10561
CRITICAL 10
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution com…
2026-06-22
CVE-2026-7664
CRITICAL 9.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project res…
2026-06-22
CVE-2026-12822
MEDIUM 4.8
Langflow — A vulnerability was identified in langflow-ai langflow up to 1.9.3. This affects an unknown function of the co…● PoC
2026-06-21
CVE-2026-3341
MEDIUM 5.4
Langflow Desktop — IBM Langflow Desktop 1.0.0 through 1.9.2 IBM Langflow is vulnerable to server-side request forgery (SSRF). Thi…
2026-06-11
CVE-2026-7787
HIGH 7.5
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information…
2026-06-11