{"data":{"ecosystem":"pypi","name":"langflow","url":"https://aisecwatch.com/packages/pypi/langflow","latestVersion":"1.12.5","firstReleaseAt":"2023-03-14T15:17:08.755Z","repository":"https://github.com/langflow-ai/langflow","llm":{"exposure":"transitive","depth":1,"integratedAt":null,"integratedVersion":null,"sdks":[],"path":["pypi:langflow","pypi:langflow-base"]},"authority":{"profile":[],"fromDependencies":[]},"dependencies":[{"ecosystem":"pypi","name":"ctransformers","versionSpec":">=0.2.10","scope":"extra:local"},{"ecosystem":"pypi","name":"langflow-base","versionSpec":"~=1.12.0","scope":"runtime"},{"ecosystem":"pypi","name":"lfx-amazon","versionSpec":"<1.0.0,>=0.1.7","scope":"runtime"},{"ecosystem":"pypi","name":"lfx-anthropic","versionSpec":"<1.0.0,>=0.1.7","scope":"runtime"},{"ecosystem":"pypi","name":"lfx-azure","versionSpec":"<1.0.0,>=0.1.0","scope":"runtime"},{"ecosystem":"pypi","name":"lfx-bundles","versionSpec":"<2.0,>=1.1.36","scope":"extra:bundles"},{"ecosystem":"pypi","name":"lfx-cohere","versionSpec":"<1.0.0,>=0.1.4","scope":"runtime"},{"ecosystem":"pypi","name":"lfx-confluent","versionSpec":"<1.0.0,>=0.1.0","scope":"extra:bundles"},{"ecosystem":"pypi","name":"lfx-datastax","versionSpec":"<1.0.0,>=0.1.9","scope":"runtime"},{"ecosystem":"pypi","name":"lfx-docling","versionSpec":"<1.0.0,>=0.1.7","scope":"runtime"},{"ecosystem":"pypi","name":"lfx-duckduckgo","versionSpec":"<1.0.0,>=0.1.5","scope":"extra:bundles"},{"ecosystem":"pypi","name":"lfx-empiriolabs","versionSpec":"<1.0.0,>=0.1.3","scope":"extra:bundles"},{"ecosystem":"pypi","name":"lfx-exa","versionSpec":"<1.0.0,>=0.1.3","scope":"extra:bundles"},{"ecosystem":"pypi","name":"lfx-google","versionSpec":"<1.0.0,>=0.2.5","scope":"runtime"},{"ecosystem":"pypi","name":"lfx-ibm","versionSpec":"<1.0.0,>=0.2.5","scope":"runtime"},{"ecosystem":"pypi","name":"lfx-ollama","versionSpec":"<1.0.0,>=0.1.1","scope":"runtime"},{"ecosystem":"pypi","name":"lfx-openai","versionSpec":"<1.0.0,>=0.1.5","scope":"runtime"},{"ecosystem":"pypi","name":"lfx-openai-compatible","versionSpec":"<1.0.0,>=0.1.5","scope":"runtime"},{"ecosystem":"pypi","name":"lfx-valkey","versionSpec":"<1.0.0,>=0.1.5","scope":"extra:bundles"},{"ecosystem":"pypi","name":"nv-ingest-client","versionSpec":"<26.3.0,>=26.1.0","scope":"extra:nv-ingest"},{"ecosystem":"pypi","name":"sentence-transformers","versionSpec":">=2.3.1","scope":"extra:local"},{"ecosystem":"pypi","name":"lfx-arxiv","versionSpec":"<1.0.0,>=0.1.5","scope":"extra:bundles"},{"ecosystem":"pypi","name":"lfx-firecrawl","versionSpec":"<1.0.0,>=0.1.3","scope":"extra:bundles"},{"ecosystem":"pypi","name":"lfx-nextplaid","versionSpec":"<1.0.0,>=0.1.6","scope":"extra:bundles"},{"ecosystem":"pypi","name":"lfx-oracle","versionSpec":"<1.0.0,>=0.1.4","scope":"runtime"},{"ecosystem":"pypi","name":"lfx-paddle","versionSpec":"<1.0.0,>=0.1.5","scope":"extra:bundles"},{"ecosystem":"pypi","name":"lfx-toolguard","versionSpec":"<1.0.0,>=0.1.2","scope":"runtime"},{"ecosystem":"pypi","name":"lfx-vllm","versionSpec":"<1.0.0,>=0.1.3","scope":"runtime"},{"ecosystem":"pypi","name":"nv-ingest-api","versionSpec":"<27.0.0,>=26.1.0","scope":"extra:nv-ingest"},{"ecosystem":"pypi","name":"cassio","versionSpec":">=0.1.7","scope":"extra:cassio"},{"ecosystem":"pypi","name":"clickhouse-connect","versionSpec":"==0.7.19","scope":"extra:clickhouse-connect"},{"ecosystem":"pypi","name":"couchbase","versionSpec":">=4.2.1","scope":"extra:couchbase"},{"ecosystem":"pypi","name":"oauthlib","versionSpec":"<5.0.0,>=4.0.0","scope":"runtime"}],"advisories":[{"id":"b0473977-f378-4d0e-b2ac-2ce4d288d4e7","url":"https://aisecwatch.com/issues/b0473977-f378-4d0e-b2ac-2ce4d288d4e7","cveId":null,"title":"GHSA-j8f7-x8jm-wmm4: Langflow: SSRF in URL-taking components (protection disabled by default / warn-only, not applied to RSS, SearXNG, Web Search, Home Assistant, Glean, Docling)","headline":null,"severity":"medium","publishedAt":"2026-10-06T13:39:57.000Z","affected":["lfx-docling@< 0.1.2 (fixed: 0.1.2)","lfx@< 1.10.3 (fixed: 1.10.3)","langflow-base@< 0.10.3 (fixed: 0.10.3)","langflow@< 1.10.3 (fixed: 1.10.3)"],"epssScore":null},{"id":"622c5e16-21c2-4d25-8cce-80721ef495bf","url":"https://aisecwatch.com/issues/622c5e16-21c2-4d25-8cce-80721ef495bf","cveId":"CVE-2026-10561","title":"GHSA-8qpj-27x8-pwpq: Langflow: PythonREPLComponent executes unsandboxed Python code, enabling authenticated RCE and privilege escalation","headline":null,"severity":"critical","publishedAt":"2026-10-06T13:38:28.000Z","affected":["langflow@< 1.10.1 (fixed: 1.10.1)"],"epssScore":0.0082},{"id":"8a7fe4b8-9e77-4d7b-9656-c1d1ad7ca23b","url":"https://aisecwatch.com/issues/8a7fe4b8-9e77-4d7b-9656-c1d1ad7ca23b","cveId":"CVE-2026-105741","title":"CVE-2026-105741: Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.5.0 until 1.10.3, an IP spoofing…","headline":"Langflow IP spoofing bypasses local-only restriction on MCP install endpoint","severity":"high","publishedAt":"2026-10-05T21:16:35.740Z","affected":["langflow@>= 1.5.0, < 1.10.3 (fixed: 1.10.3)"],"epssScore":0.00212},{"id":"bc3f64bf-002c-43f6-9e92-bccba1a8ff58","url":"https://aisecwatch.com/issues/bc3f64bf-002c-43f6-9e92-bccba1a8ff58","cveId":"CVE-2026-105699","title":"CVE-2026-105699: Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.6.8 until 1.9.1, Langflow…","headline":"Langflow MCP resource read exposes other users' flow files","severity":"high","publishedAt":"2026-10-05T21:16:35.410Z","affected":["langflow@>= 1.6.8, <= 1.9.0 (fixed: 1.9.1)"],"epssScore":0.00246},{"id":"051270ac-41e7-4b62-b655-2ca3afb01fe1","url":"https://aisecwatch.com/issues/051270ac-41e7-4b62-b655-2ca3afb01fe1","cveId":"CVE-2026-105698","title":"CVE-2026-105698: Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.0.0 until 1.10.1, Langflow did…","headline":"Langflow flow ownership bypass in deprecated build vertices endpoints","severity":"medium","publishedAt":"2026-10-05T21:16:35.257Z","affected":["langflow@>= 1.0.0, < 1.10.1 (fixed: 1.10.1)","langflow-base@< 0.10.1 (fixed: 0.10.1)"],"epssScore":0.00177},{"id":"4b29cc58-37e5-47d3-9fc9-f5326011ee11","url":"https://aisecwatch.com/issues/4b29cc58-37e5-47d3-9fc9-f5326011ee11","cveId":"CVE-2026-105697","title":"CVE-2026-105697: Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP stdio…","headline":"Langflow arbitrary command execution through MCP stdio server configuration","severity":"critical","publishedAt":"2026-10-05T21:16:35.087Z","affected":["langflow@>= 1.1.2, < 1.10.3 (fixed: 1.10.3)","langflow-base@>= 0.1.2, < 0.10.3 (fixed: 0.10.3)","lfx@< 1.10.3 (fixed: 1.10.3)"],"epssScore":0.00396},{"id":"641a9849-8cec-41df-9eb8-711bfa3821e4","url":"https://aisecwatch.com/issues/641a9849-8cec-41df-9eb8-711bfa3821e4","cveId":"CVE-2026-51886","title":"CVE-2026-51886: langflow-ai langflow v1.9.3 is affected by: Code Injection. The impact is: execute arbitrary code (remote). The…","headline":"Langflow code injection in /api/v1/validate/code endpoint","severity":"critical","publishedAt":"2026-10-01T22:17:03.387Z","affected":["langflow@>= 1.7.2, < 1.10.1 (fixed: 1.10.1)"],"epssScore":0.00403},{"id":"b209a5d1-dee3-46f1-a94c-03e46b2ed198","url":"https://aisecwatch.com/issues/b209a5d1-dee3-46f1-a94c-03e46b2ed198","cveId":"CVE-2026-9205","title":"CVE-2026-9205: IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.","headline":"IBM Langflow OSS weak key derivation in ensure_fernet_key()","severity":"high","publishedAt":"2026-08-05T19:17:49.193Z","affected":["langflow@<= 1.10.0 (fixed: 1.10.1)"],"epssScore":0.00302},{"id":"d35683bc-4ed4-4e2e-9a27-8b92dea12002","url":"https://aisecwatch.com/issues/d35683bc-4ed4-4e2e-9a27-8b92dea12002","cveId":"CVE-2026-8505","title":"CVE-2026-8505: IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows…","headline":"IBM Langflow OSS unauthenticated flow execution through webhook authentication","severity":"critical","publishedAt":"2026-07-17T20:17:31.417Z","affected":["langflow@>= 1.7.0, <= 1.9.0 (fixed: 1.9.1)"],"epssScore":0.00719},{"id":"94956f48-8b7c-4e88-9e99-04405ca53a87","url":"https://aisecwatch.com/issues/94956f48-8b7c-4e88-9e99-04405ca53a87","cveId":"CVE-2026-55447","title":"GHSA-ccv6-r384-xp75: Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit","headline":null,"severity":"critical","publishedAt":"2026-06-19T21:18:24.000Z","affected":["langflow@< 1.9.2 (fixed: 1.9.2)"],"epssScore":0.00662},{"id":"c7f9dfea-f348-4bd1-83d5-34646e736817","url":"https://aisecwatch.com/issues/c7f9dfea-f348-4bd1-83d5-34646e736817","cveId":"CVE-2026-55446","title":"GHSA-qwqc-p3q8-wcg9: Langflow: Unauthenticated DoS through multipart form boundary file upload","headline":null,"severity":"high","publishedAt":"2026-06-19T21:17:37.000Z","affected":["langflow@< 1.0.19 (fixed: 1.0.19)"],"epssScore":0.00581},{"id":"0283ba9f-be31-458e-8bed-c595346e9d7a","url":"https://aisecwatch.com/issues/0283ba9f-be31-458e-8bed-c595346e9d7a","cveId":"CVE-2026-55423","title":"GHSA-7hw8-6q6r-4276: Langflow: Logout button does not clear session","headline":null,"severity":"medium","publishedAt":"2026-06-19T21:17:01.000Z","affected":["langflow@< 1.7.0 (fixed: 1.7.1)"],"epssScore":0.00222},{"id":"65d195e2-8f57-4f0c-9098-30d8d8b5c6ce","url":"https://aisecwatch.com/issues/65d195e2-8f57-4f0c-9098-30d8d8b5c6ce","cveId":"CVE-2026-55255","title":"GHSA-qrpv-q767-xqq2: Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow","headline":null,"severity":"critical","publishedAt":"2026-06-19T21:16:46.000Z","affected":["langflow@< 1.9.1 (fixed: 1.9.1)"],"epssScore":0.00887},{"id":"af75fe66-33f5-4086-b3d6-69fcdb3c7052","url":"https://aisecwatch.com/issues/af75fe66-33f5-4086-b3d6-69fcdb3c7052","cveId":"CVE-2026-55450","title":"GHSA-x223-p2gf-v735: Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak","headline":null,"severity":"critical","publishedAt":"2026-06-17T18:43:12.000Z","affected":["langflow@< 1.9.1 (fixed: 1.9.1)"],"epssScore":0.0119},{"id":"cb124a58-2e09-4e88-a926-05a57aa42c41","url":"https://aisecwatch.com/issues/cb124a58-2e09-4e88-a926-05a57aa42c41","cveId":"CVE-2026-48520","title":"GHSA-rcjh-r59h-gq37: Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read","headline":null,"severity":"medium","publishedAt":"2026-06-16T17:36:00.000Z","affected":["langflow@< 1.10.0 (fixed: 1.10.0)"],"epssScore":0.00437},{"id":"817a67eb-8b07-4cde-bb90-270e166462b0","url":"https://aisecwatch.com/issues/817a67eb-8b07-4cde-bb90-270e166462b0","cveId":"CVE-2026-48519","title":"GHSA-v5ff-9q35-q26f: Langflow: Unauthenticated RCE in Shareable Playgrounds","headline":null,"severity":"critical","publishedAt":"2026-06-16T17:35:32.000Z","affected":["langflow@<= 1.9.1 (fixed: 1.9.2)"],"epssScore":0.00783},{"id":"a3dce035-d72f-4a79-83b7-53750dff26c4","url":"https://aisecwatch.com/issues/a3dce035-d72f-4a79-83b7-53750dff26c4","cveId":"CVE-2026-42867","title":"GHSA-79ph-745m-6wxq: Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint","headline":null,"severity":"medium","publishedAt":"2026-06-16T17:35:09.000Z","affected":["langflow@<= 1.8.4 (fixed: 1.9.0)"],"epssScore":0.00466},{"id":"12ca8d05-4d10-4213-a0f5-d8996d421e88","url":"https://aisecwatch.com/issues/12ca8d05-4d10-4213-a0f5-d8996d421e88","cveId":"CVE-2026-33760","title":"GHSA-9c59-2mvc-vfr8: Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints ","headline":null,"severity":"high","publishedAt":"2026-06-16T17:34:21.000Z","affected":["langflow@< 1.9.0 (fixed: 1.9.0)"],"epssScore":0.00495},{"id":"3f65faa7-36c7-43f5-9472-4d2317e2177f","url":"https://aisecwatch.com/issues/3f65faa7-36c7-43f5-9472-4d2317e2177f","cveId":"CVE-2026-42048","title":"CVE-2026-42048: Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable…","headline":"Langflow path traversal in Knowledge Bases API DELETE endpoint","severity":"critical","publishedAt":"2026-05-12T18:17:23.780Z","affected":["langflow@<= 1.8.4 (fixed: 1.9.0)"],"epssScore":0.00601},{"id":"f12fa6ab-4972-4cae-a3e0-e0e361ea4868","url":"https://aisecwatch.com/issues/f12fa6ab-4972-4cae-a3e0-e0e361ea4868","cveId":"CVE-2026-7700","title":"CVE-2026-7700: A weakness has been identified in langflow-ai langflow up to 1.8.4. This affects the function eval of the file…","headline":"Langflow code injection in eval of lambda_filter component","severity":"medium","publishedAt":"2026-05-03T15:15:59.693Z","affected":["langflow@>= 1.3.0, < 1.10.3 (fixed: 1.10.3)"],"epssScore":0.00314},{"id":"4dabfc8a-7b83-4fc5-9596-4b043992704b","url":"https://aisecwatch.com/issues/4dabfc8a-7b83-4fc5-9596-4b043992704b","cveId":"CVE-2026-6599","title":"CVE-2026-6599: A vulnerability was detected in langflow-ai langflow up to 1.8.3. The impacted element is the function…","headline":"Langflow injection through X-Forwarded-For in MCP project configuration API","severity":"medium","publishedAt":"2026-04-20T04:16:53.060Z","affected":["langflow@<= 1.8.3"],"epssScore":0.00393},{"id":"6346f206-473e-4c67-8a75-1fd8254bdb89","url":"https://aisecwatch.com/issues/6346f206-473e-4c67-8a75-1fd8254bdb89","cveId":"CVE-2026-6598","title":"CVE-2026-6598: A security vulnerability has been detected in langflow-ai langflow up to 1.8.3. The affected element is the function…","headline":"Langflow cleartext storage of auth settings in project creation","severity":"medium","publishedAt":"2026-04-20T04:16:52.857Z","affected":["langflow@< 1.9.1 (fixed: 1.9.1)"],"epssScore":0.00242},{"id":"9b32743c-4295-4984-b636-1022b0899849","url":"https://aisecwatch.com/issues/9b32743c-4295-4984-b636-1022b0899849","cveId":"CVE-2026-6597","title":"CVE-2026-6597: A weakness has been identified in langflow-ai langflow up to 1.8.3. Impacted is the function…","headline":"Langflow stores API credentials unprotected in Flow Using API component","severity":"low","publishedAt":"2026-04-20T03:16:17.153Z","affected":["langflow@<= 1.8.3"],"epssScore":0.00377},{"id":"1ea39ccd-550a-4800-b435-7cb727f1f74a","url":"https://aisecwatch.com/issues/1ea39ccd-550a-4800-b435-7cb727f1f74a","cveId":"CVE-2026-33873","title":"CVE-2026-33873: Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.9.0, the Agentic…","headline":"Langflow arbitrary Python execution through Agentic Assistant validation","severity":"critical","publishedAt":"2026-03-27T21:17:23.953Z","affected":["langflow@<= 1.8.1 (fixed: 1.9.0)"],"epssScore":0.01816},{"id":"aadae2dd-557a-4880-895d-7265c9e755a2","url":"https://aisecwatch.com/issues/aadae2dd-557a-4880-895d-7265c9e755a2","cveId":"CVE-2026-34046","title":"GHSA-8c4j-f57c-35cf: Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check","headline":null,"severity":"high","publishedAt":"2026-03-27T19:36:23.000Z","affected":["langflow-base@<= 0.5.0 (fixed: 0.5.1)","langflow@<= 1.5.0 (fixed: 1.5.1)"],"epssScore":0.00681},{"id":"246f8438-faca-43db-87c9-93991713d22a","url":"https://aisecwatch.com/issues/246f8438-faca-43db-87c9-93991713d22a","cveId":"CVE-2026-33497","title":"GHSA-ph9w-r52h-28p7: langflow: /profile_pictures/{folder_name}/{file_name} endpoint file reading","headline":null,"severity":"high","publishedAt":"2026-03-20T20:56:14.000Z","affected":["langflow@< 1.7.1 (fixed: 1.7.1)"],"epssScore":0.02028},{"id":"ca508225-246e-49f0-8f73-3d4331b696df","url":"https://aisecwatch.com/issues/ca508225-246e-49f0-8f73-3d4331b696df","cveId":"CVE-2026-33484","title":"GHSA-7grx-3xcx-2xv5: langflow has Unauthenticated IDOR on Image Downloads","headline":null,"severity":"high","publishedAt":"2026-03-20T20:47:10.000Z","affected":["langflow@>= 1.0.0, <= 1.8.1"],"epssScore":0.00559},{"id":"b6d1091b-f7a7-4587-a962-1417cbf3f629","url":"https://aisecwatch.com/issues/b6d1091b-f7a7-4587-a962-1417cbf3f629","cveId":"CVE-2026-33309","title":"GHSA-g2j9-7rj2-gm6c: Langflow has an Arbitrary File Write (RCE) via v2 API","headline":null,"severity":"critical","publishedAt":"2026-03-19T17:46:43.000Z","affected":["langflow@>= 1.2.0, <= 1.8.1 (fixed: 1.9.0)"],"epssScore":0.01048},{"id":"769da157-3f88-4b98-ae0f-7203f64ebb85","url":"https://aisecwatch.com/issues/769da157-3f88-4b98-ae0f-7203f64ebb85","cveId":"CVE-2026-33053","title":"GHSA-rf6x-r45m-xv3w: Langflow is Missing Ownership Verification in API Key Deletion (IDOR)","headline":null,"severity":"high","publishedAt":"2026-03-18T12:58:35.000Z","affected":["langflow@< 1.7.2 (fixed: 1.7.2)"],"epssScore":0.00524},{"id":"3fabc75b-6c92-4d26-90e2-da7789f22067","url":"https://aisecwatch.com/issues/3fabc75b-6c92-4d26-90e2-da7789f22067","cveId":"CVE-2026-33017","title":"GHSA-vwmf-pq79-vjvx: Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint","headline":null,"severity":"critical","publishedAt":"2026-03-17T20:05:05.000Z","affected":["langflow@<= 1.8.1"],"epssScore":0.24755},{"id":"cd318589-0307-4d0a-82c2-8035259c787e","url":"https://aisecwatch.com/issues/cd318589-0307-4d0a-82c2-8035259c787e","cveId":"CVE-2026-27966","title":"CVE-2026-27966: Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent…","headline":"Langflow CSV Agent code execution through prompt injection","severity":"critical","publishedAt":"2026-02-26T02:16:23.833Z","affected":["langflow@<= 1.8.0rc2"],"epssScore":0.02492},{"id":"a85571c9-2de9-4897-89cf-44502d82d129","url":"https://aisecwatch.com/issues/a85571c9-2de9-4897-89cf-44502d82d129","cveId":"CVE-2026-0770","title":"CVE-2026-0770: Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability…","headline":"Langflow remote code execution through exec_globals in the validate endpoint","severity":"critical","publishedAt":"2026-01-23T09:16:04.063Z","affected":["langflow@<= 1.7.3"],"epssScore":0.63013},{"id":"82e82402-304a-4c9a-8756-ce4055766e62","url":"https://aisecwatch.com/issues/82e82402-304a-4c9a-8756-ce4055766e62","cveId":"CVE-2026-21445","title":"CVE-2026-21445: Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0.dev45, multiple…","headline":"Langflow missing authentication on API endpoints exposes user data","severity":"critical","publishedAt":"2026-01-03T01:16:17.880Z","affected":["langflow-base@<= 0.6.9 (fixed: 0.7.1)","langflow@<= 1.7.0.dev44 (fixed: 1.7.1)"],"epssScore":0.33289},{"id":"b5b01c41-1938-4989-be4d-075e5dc13eda","url":"https://aisecwatch.com/issues/b5b01c41-1938-4989-be4d-075e5dc13eda","cveId":"CVE-2025-68478","title":"CVE-2025-68478: Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, if an arbitrary…","headline":"Langflow arbitrary file write through the fs_path request field","severity":"high","publishedAt":"2025-12-19T23:15:51.623Z","affected":["langflow@< 1.7.1 (fixed: 1.7.1)"],"epssScore":0.05787},{"id":"639cfcf2-1493-4b2f-8408-8e1d3767d3f9","url":"https://aisecwatch.com/issues/639cfcf2-1493-4b2f-8408-8e1d3767d3f9","cveId":"CVE-2025-68477","title":"CVE-2025-68477: Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, Langflow…","headline":"Langflow server-side request forgery through the API Request component","severity":"high","publishedAt":"2025-12-19T22:15:53.547Z","affected":["langflow@< 1.7.1 (fixed: 1.7.1)"],"epssScore":0.06303},{"id":"e3ce50d7-e9e6-4a9d-98f7-d0ca32be3dc8","url":"https://aisecwatch.com/issues/e3ce50d7-e9e6-4a9d-98f7-d0ca32be3dc8","cveId":"CVE-2025-34291","title":"CVE-2025-34291: Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote…","headline":"Langflow account takeover and remote code execution via CORS and refresh token","severity":"high","publishedAt":"2025-12-06T04:15:47.433Z","affected":["langflow@<= 1.6.9 (fixed: 1.7.0)"],"epssScore":0.92808},{"id":"27cb2db8-d2b1-4dc7-8812-15f56e9e52f2","url":"https://aisecwatch.com/issues/27cb2db8-d2b1-4dc7-8812-15f56e9e52f2","cveId":"CVE-2025-57760","title":"CVE-2025-57760: Langflow is a tool for building and deploying AI-powered agents and workflows. A privilege escalation vulnerability…","headline":"Langflow privilege escalation in containers via langflow superuser CLI command","severity":"high","publishedAt":"2025-08-25T21:15:30.140Z","affected":["langflow@<= 1.5.0 (fixed: 1.5.1)","langflow-base@<= 0.5.0 (fixed: 0.5.1)"],"epssScore":0.00518},{"id":"ab9ba187-619a-49b9-8037-afb336f16870","url":"https://aisecwatch.com/issues/ab9ba187-619a-49b9-8037-afb336f16870","cveId":"CVE-2025-3248","title":"CVE-2025-3248: Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and x","headline":"Langflow code injection in /api/v1/validate/code endpoint","severity":"critical","publishedAt":"2025-04-07T19:15:44.897Z","affected":["langflow@< 1.3.0 (fixed: 1.3.0)","langflow-base@< 0.3.0 (fixed: 0.3.0)"],"epssScore":0.99993},{"id":"224d8b4f-00e7-4eba-bb0c-060e8214cf59","url":"https://aisecwatch.com/issues/224d8b4f-00e7-4eba-bb0c-060e8214cf59","cveId":"CVE-2024-48061","title":"CVE-2024-48061: langflow <=1.0.18 is vulnerable to Remote Code Execution (RCE) as any component provided the code functionality and the…","headline":"langflow remote code execution through components running outside a sandbox","severity":"critical","publishedAt":"2024-11-05T04:15:04.560Z","affected":["langflow@<= 1.0.18"],"epssScore":0.01541},{"id":"9e0d6927-4893-43d8-9dad-98907f3b3ccf","url":"https://aisecwatch.com/issues/9e0d6927-4893-43d8-9dad-98907f3b3ccf","cveId":"CVE-2024-42835","title":"CVE-2024-42835: langflow v1.0.12 was discovered to contain a remote code execution (RCE) vulnerability via the PythonCodeTool…","headline":"langflow remote code execution via the PythonCodeTool component","severity":"critical","publishedAt":"2024-10-31T18:15:05.610Z","affected":["langflow@<= 1.0.12"],"epssScore":0.01164},{"id":"fb173eb4-bfed-4a8e-9818-ee3eb00e0d81","url":"https://aisecwatch.com/issues/fb173eb4-bfed-4a8e-9818-ee3eb00e0d81","cveId":"CVE-2024-9277","title":"CVE-2024-9277: A vulnerability classified as problematic was found in Langflow up to 1.0.18. Affected by this vulnerability is an…","headline":"Langflow regular expression complexity flaw in HTTP POST request handler","severity":"low","publishedAt":"2024-09-27T15:15:14.400Z","affected":["langflow@<= 1.0.18"],"epssScore":0.00963},{"id":"a70c5976-b4d2-4b5f-a1e0-a51d8eb51828","url":"https://aisecwatch.com/issues/a70c5976-b4d2-4b5f-a1e0-a51d8eb51828","cveId":"CVE-2024-37014","title":"CVE-2024-37014: Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the \"POST…","headline":"Langflow remote code execution through custom component endpoint","severity":"critical","publishedAt":"2024-06-11T00:15:15.213Z","affected":["langflow@< 1.0.15 (fixed: 1.0.15)"],"epssScore":0.63674}],"checkedAt":"2026-10-09T21:49:04.766Z"},"meta":{"advisoryMatching":"by package name; advisory records do not state an ecosystem"}}