← Browse

Langflow

42 CVEs
CVE IDSeverityProduct / summaryPublished
CVE-2026-18545 MEDIUM 4.3 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.11.1 is vulnerable to server-side request forgery (SSRF). This may allow an a… 2026-08-28 CVE-2026-18729 HIGH 8.8 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code du… 2026-08-28 CVE-2026-18891 HIGH 8.2 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sens… 2026-08-28 CVE-2026-18899 HIGH 7.5 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbitrary files due to path traver… 2026-08-28 CVE-2026-18904 HIGH 8.2 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject… 2026-08-28 CVE-2026-19286 CRITICAL 9.8 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper … 2026-08-28 CVE-2026-19294 MEDIUM 6.4 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute and read any user… 2026-08-28 CVE-2026-19295 CRITICAL 9.9 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system c… 2026-08-28 CVE-2026-19875 HIGH 7.5 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email informati… 2026-08-19 CVE-2026-19297 CRITICAL 9.1 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accou… 2026-08-13 CVE-2026-10128 MEDIUM 6.5 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to … 2026-08-05 CVE-2026-10547 MEDIUM 5.9 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/buil… 2026-08-05 CVE-2026-17623 HIGH 8.8 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary command… 2026-08-05 CVE-2026-17624 HIGH 8.5 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0… 2026-08-05 CVE-2026-17625 HIGH 7.2 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0… 2026-08-05 CVE-2026-17626 HIGH 8.8 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expos… 2026-08-05 CVE-2026-17630 HIGH 7.2 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper … 2026-08-05 CVE-2026-17632 HIGH 8.8 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code du… 2026-08-05 CVE-2026-17633 HIGH 8.5 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code du… 2026-08-05 CVE-2026-7646 MEDIUM 6.5 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, includi… 2026-08-05 CVE-2026-7657 MEDIUM 6.5 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplet… 2026-08-05 CVE-2026-7658 MEDIUM 6.5 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inj… 2026-08-05 CVE-2026-7869 MEDIUM 5.4 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v… 2026-08-05 CVE-2026-8182 HIGH 8.8 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on … 2026-08-05 CVE-2026-8183 HIGH 7.7 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0… 2026-08-05 CVE-2026-8446 HIGH 7.5 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Prot… 2026-08-05 CVE-2026-8470 HIGH 7.4 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 us… 2026-08-05 CVE-2026-8478 HIGH 8.8 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, du… 2026-08-05 CVE-2026-9077 HIGH 8.5 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only … 2026-08-05 CVE-2026-9081 HIGH 7.1 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) … 2026-08-05 CVE-2026-9130 HIGH 7.1 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent tha… 2026-08-05 CVE-2026-9196 HIGH 8.1 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during … 2026-08-05 CVE-2026-9201 HIGH 8.8 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a… 2026-08-05 CVE-2026-9205 HIGH 7.4 Langflow Oss — IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() functio… 2026-08-05 CVE-2026-10700 MEDIUM 6.5 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handl… 2026-07-30 CVE-2026-12940 CRITICAL 9.8 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment… 2026-07-30 CVE-2026-12942 HIGH 7.5 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An … 2026-07-30 CVE-2026-12945 HIGH 7.1 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build j… 2026-07-30 CVE-2026-12946 CRITICAL 9.9 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, du… 2026-07-30 CVE-2026-13435 CRITICAL 9.9 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sa… 2026-07-30 CVE-2026-13444 HIGH 8.1 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents … 2026-07-30 CVE-2026-13442 HIGH 7.1 Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access … 2026-07-28