Skip to content
MediumVulnerability

GHSA-j8f7-x8jm-wmm4: Langflow: SSRF in URL-taking components (protection disabled by default / warn-only, not applied to RSS, SearXNG, Web Search, Home Assistant, Glean, Docling)

Published
Record updated
View JSON
Affected
  • lfx-docling < 0.1.2, fixed in 0.1.2
  • lfx < 1.10.3, fixed in 1.10.3
  • langflow-base < 0.10.3, fixed in 0.10.3
  • and 1 more

Summary

Before Langflow 1.10.3, several built-in components, including RSS Reader, SearXNG, Web Search, Home Assistant, Glean Search and Docling Serve, sent server-side requests to flow-author-controlled URLs with no SSRF enforcement. An authenticated user who can build or run flows could reach loopback, private, link-local and cloud metadata addresses and often read the response back through the component output.

Mitigation

Fixed in Langflow 1.10.3 (and 1.11.0+), with patched versions langflow 1.10.3, langflow-base 0.10.3, lfx 1.10.3 and lfx-docling 0.1.2. With default settings, outbound requests from these components are now validated after DNS resolution, pinned to the validated IP, and blocked for private, loopback, link-local or metadata addresses unless the operator allowlists the host.