Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Langflow — Vulnerabilities & Security Advisories 43

All 43 CVE vulnerabilities found in Langflow, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of security vulnerabilities affecting Langflow, an open-source framework designed for building generative AI applications. It focuses on tracking Common Weakness Enumerations (CWEs) and Common Vulnerabilities and Exposures (CVEs) associated with this specific software product. The vulnerability database here collects data spanning multiple years, capturing both historical and recent security incidents. It includes flaws related to authentication bypass, injection attacks, improper access control, and insecure configuration settings that may arise from the integration of various AI components or the underlying infrastructure. The scope covers issues identified in the core framework as well as those linked to its extension ecosystem. By reviewing this aggregated data, security professionals and developers can track Langflow’s vendor advisories to stay informed about critical patches and mitigation strategies. Users can also gain a deeper understanding of specific weakness classes prevalent in similar AI-driven software by analyzing patterns in the reported bugs. Furthermore, the page allows for a detailed lookup of Langflow’s vulnerability history, enabling teams to assess risk exposure, compare severity levels, and prioritize remediation efforts based on real-world exploitation data and community feedback. This resource serves as a centralized reference for understanding the security posture of Langflow over time.

Vendor: n/a

CVE IDTitleCVSSSeverityPublished
CVE-2026-48520 Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read CWE-73 6.1 Medium2026-06-23
CVE-2026-33760 Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints CWE-639 8.8 High2026-06-23
CVE-2026-42867 Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint CWE-22 6.5 Medium2026-06-23
CVE-2026-55255 Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow CWE-639 8.4 High2026-06-23
CVE-2026-55423 Langflow: Logout button does not clear session CWE-613 6.1 Medium2026-06-23
CVE-2026-55446 Langflow: Unauthenticated DoS through multipart form boundary file upload CWE-400 7.5 High2026-06-23
CVE-2026-48519 Langflow: Unauthenticated RCE in Shareable Playgrounds CWE-94 9.6 Critical2026-06-23
CVE-2026-55447 Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit CWE-61 9.6 Critical2026-06-23
CVE-2026-55450 Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak CWE-200 9.3 Critical2026-06-23
CVE-2026-12822 langflow-ai langflow Bundle URL Loader code injection CWE-94 5.3 Medium2026-06-21
CVE-2026-42048 Langflow: Path Traversal in Langflow Knowledge Bases API CWE-22 9.6 Critical2026-05-12
CVE-2026-7700 langflow-ai langflow LambdaFilterComponent lambda_filter.p eval code injection CWE-94 6.3 Medium2026-05-03
CVE-2026-7687 langflow-ai langflow Full Builtins code_parser.py CodeParser.parse_callable_details command injection CWE-77 6.3 Medium2026-05-03
CVE-2026-6600 langflow-ai langflow Frontend React Component Rendering edit-message.tsx cross site scripting CWE-79 3.5 Low2026-04-20
CVE-2026-6599 langflow-ai langflow Model Context Protocol Configuration API mcp_projects.py install_mcp_config injection CWE-74 6.3 Medium2026-04-20
CVE-2026-6598 langflow-ai langflow Project Creation Endpoint projects.py encrypt_auth_settings cleartext storage in file CWE-313 4.3 Medium2026-04-20
CVE-2026-6597 langflow-ai langflow Flow Using API core.py has_api_terms credentials storage CWE-256 2.7 Low2026-04-20
CVE-2026-6596 langflow-ai langflow API Endpoint endpoints.py create_upload_file unrestricted upload CWE-434 7.3 High2026-04-20
CVE-2026-34046 Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check CWE-639 8.2 -2026-03-27
CVE-2026-33873 Langflow has Authenticated Code Execution in Agentic Assistant Validation CWE-94 8.8 -2026-03-27
CVE-2026-5027 Langflow - Path Traversal Arbitrary File Write via upload_user_file CWE-22 8.8 High2026-03-27
CVE-2026-5026 Langflow - Stored XSS via Malicious SVG Upload CWE-79 5.4 -2026-03-27
CVE-2026-5025 Langflow - Application Logs Exposed to All Authenticated Users CWE-862 6.5 Medium2026-03-27
CVE-2026-5022 Langflow - Missing Authorization on download_image Endpoint CWE-862 5.3 -2026-03-27
CVE-2026-33497 Langflow: /profile_pictures/{folder_name}/{file_name} endpoint file reading CWE-22 6.5 -2026-03-24
CVE-2026-33484 Langflow has Unauthenticated IDOR on Image Downloads CWE-284 7.5 High2026-03-24
CVE-2026-33475 Langflow GitHub Actions Shell Injection CWE-74 9.1 Critical2026-03-24
CVE-2026-33309 Langflow has an Arbitrary File Write (RCE) via v2 API CWE-22 10.0 Critical2026-03-24
CVE-2026-33053 Langflow has Missing Ownership Verification in API Key Deletion (IDOR) CWE-639 8.2 -2026-03-20
CVE-2026-33017 Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint CWE-94 9.8 -2026-03-20

All 43 known CVE vulnerabilities affecting Langflow with full Chinese analysis, references, and POCs where available.