Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Langflow OSS — Vulnerabilities & Security Advisories 67

All 67 CVE vulnerabilities found in Langflow OSS, with AI-generated Chinese analysis, references, and POCs.

This page details Common Vulnerabilities and Exposures associated with Langflow, an open-source framework for building AI agents. It specifically addresses the weakness types affecting this vendor’s software product. The collection aggregates reported security flaws within Langflow OSS, covering a broad spectrum of issues including injection attacks, broken access control, and improper neutralization of input during web page generation. The data spans from the initial public release of the framework through recent updates, ensuring a comprehensive view of historical and ongoing security concerns. This time range captures the evolution of the product’s threat landscape as new features and dependencies were introduced over time. Visitors to this resource can effectively track a vendor’s advisories by reviewing how Langflow has responded to specific incidents. Users can also understand a weakness class by analyzing common patterns in how these vulnerabilities were exploited or mitigated within the codebase. Furthermore, researchers and security professionals can look up a product's vulnerability history to assess its stability and security posture relative to other similar tools. This aggregation serves as a factual reference point for risk assessment, allowing stakeholders to identify potential exposures without needing to sift through raw, unstructured data. By centralizing this information, the page facilitates a clearer understanding of the security implications inherent in using or deploying Langflow in production environments.

Vendor: IBM

CVE IDTitleCVSSSeverityPublished
CVE-2026-17624 Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling CWE-94 8.5 High2026-08-05
CVE-2026-17633 Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling CWE-94 8.5 High2026-08-05
CVE-2026-17632 Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling CWE-94 8.8 High2026-08-05
CVE-2026-9196 Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling CWE-94 8.1 High2026-08-05
CVE-2026-8182 Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling CWE-94 8.8 High2026-08-05
CVE-2026-9201 Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling CWE-326 8.8 High2026-08-05
CVE-2026-8478 Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling CWE-94 8.8 High2026-08-05
CVE-2026-8183 Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement CWE-22 7.7 High2026-08-05
CVE-2026-7658 Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement CWE-22 6.5 Medium2026-08-05
CVE-2026-9130 Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement 7.1 High2026-08-05
CVE-2026-10547 Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement CWE-284 5.9 Medium2026-08-05
CVE-2026-7869 Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement CWE-22 5.4 Medium2026-08-05
CVE-2026-8470 Langflow is affected by weaknesses in secret handling and sensitive configuration access CWE-327 7.4 High2026-08-05
CVE-2026-9205 Langflow is affected by weaknesses in secret handling and sensitive configuration access CWE-338 7.4 High2026-08-05
CVE-2026-10128 Langflow is affected by weaknesses in secret handling and sensitive configuration access CWE-200 6.5 Medium2026-08-05
CVE-2026-9081 Langflow OSS is affected by server-side request forgery in provider validation and API request functionality CWE-918 7.1 High2026-08-05
CVE-2026-7657 Langflow OSS is affected by server-side request forgery in provider validation and API request functionality CWE-918 6.5 Medium2026-08-05
CVE-2026-17625 Langflow is affected by OS Command Injection in Model Context Protocol features CWE-78 7.2 High2026-08-05
CVE-2026-17623 Langflow is affected OS Command Injection in Model Context Protocol features CWE-78 8.8 High2026-08-05
CVE-2026-17630 Langflow is affected by security vulnerabilities in Model Context Protocol features CWE-184 7.2 High2026-08-05
CVE-2026-17626 Langflow is affected by security vulnerabilities in Model Context Protocol features CWE-266 8.8 High2026-08-05
CVE-2026-8446 Langflow is affected by security vulnerabilities in Model Context Protocol features CWE-306 7.5 High2026-08-05
CVE-2026-7646 Langflow is affected by security vulnerabilities in Model Context Protocol features CWE-22 6.5 Medium2026-08-05
CVE-2026-9077 Reliance on Untrusted Inputs in a Security Decision vulnerabilities in Model Context Protocol features CWE-807 8.5 High2026-08-05
CVE-2026-12946 Remote Code Execution in CUGA Component CodeAgent CWE-94 9.9 Critical2026-07-30
CVE-2026-13444 Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints CWE-520--2026-07-30
CVE-2026-10700 Broken Access Control Vulnerabilities in Langflow 1.0.0 - 1.8.4 File Handling API Allowed Unauthorized Access to User Files CWE-639 6.5 Medium2026-07-30
CVE-2026-13435 Python Interpreter Sandbox Bypass Leading to Sensitive Data Exposure CWE-94 9.9 Critical2026-07-30
CVE-2026-12942 Langflow is affected by path traversal due to multiple unauthenticated and insufficiently authorized API endpoints CWE-22 7.5 High2026-07-30
CVE-2026-12945 Langflow is affected by exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints CWE-639 7.1 High2026-07-30

All 67 known CVE vulnerabilities affecting Langflow OSS with full Chinese analysis, references, and POCs where available.