Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| langflow-ai | langflow | < 1.9.2 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55255 | 9.9 CRITICAL | Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attacker |
| CVE-2026-55447 | 9.6 CRITICAL | Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit |
| CVE-2026-55450 | 9.3 CRITICAL | Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak |
| CVE-2026-33760 | 8.8 HIGH | Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints |
| CVE-2026-55446 | 7.5 HIGH | Langflow: Unauthenticated DoS through multipart form boundary file upload |
| CVE-2026-42867 | 6.5 MEDIUM | Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint |
| CVE-2026-48520 | 6.1 MEDIUM | Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read |
| CVE-2026-55423 | 6.1 MEDIUM | Langflow: Logout button does not clear session |
No comments yet