All 67 CVE vulnerabilities found in Langflow OSS, with AI-generated Chinese analysis, references, and POCs.
This page details Common Vulnerabilities and Exposures associated with Langflow, an open-source framework for building AI agents. It specifically addresses the weakness types affecting this vendor’s software product. The collection aggregates reported security flaws within Langflow OSS, covering a broad spectrum of issues including injection attacks, broken access control, and improper neutralization of input during web page generation. The data spans from the initial public release of the framework through recent updates, ensuring a comprehensive view of historical and ongoing security concerns. This time range captures the evolution of the product’s threat landscape as new features and dependencies were introduced over time. Visitors to this resource can effectively track a vendor’s advisories by reviewing how Langflow has responded to specific incidents. Users can also understand a weakness class by analyzing common patterns in how these vulnerabilities were exploited or mitigated within the codebase. Furthermore, researchers and security professionals can look up a product's vulnerability history to assess its stability and security posture relative to other similar tools. This aggregation serves as a factual reference point for risk assessment, allowing stakeholders to identify potential exposures without needing to sift through raw, unstructured data. By centralizing this information, the page facilitates a clearer understanding of the security implications inherent in using or deploying Langflow in production environments.
Vendor: IBM
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-7874 | Weak Cryptographic Key Derivation Exposed All Stored Credentials CWE-338 | 9.1 | Critical | 2026-06-30 |
| CVE-2026-7664 | Unauthenticated Flow Execution via Webhook Endpoint in Langflow OSS CWE-287 | 9.8 | Critical | 2026-06-22 |
| CVE-2026-10561 | Unauthenticated Remote Code Execution in Langflow OSS PythonREPLComponent via Builtins Injection CWE-94 | 10.0 | Critical | 2026-06-22 |
| CVE-2026-7787 | Unauthenticated Session History Access via Public Flow Execution CWE-639 | 7.5 | High | 2026-06-11 |
| CVE-2026-7528 | Unauthenticated File Upload Vulnerability Allows Disk Space Exhaustion and Path Disclosure in Langflow OSS CWE-400 | 7.1 | High | 2026-05-27 |
| CVE-2026-7524 | Path Traversal Vulnerability in File Processing Components Allows Unauthorized File System Access and Potential Remote Code Execution CWE-22 | 9.8 | Critical | 2026-05-27 |
| CVE-2026-6542 | Monitor API allows cross-user read of transaction logs and deletion of build data via flow_id CWE-639 | 6.5 | Medium | 2026-04-30 |
All 67 known CVE vulnerabilities affecting Langflow OSS with full Chinese analysis, references, and POCs where available.