GHSA-j8f7-x8jm-wmm4: Langflow: SSRF in URL-taking components (protection disabled by default / warn-only, not applied to RSS, SearXNG, Web Search, Home Assistant, Glean, Docling)
- Identifier
- GHSA-j8f7-x8jm-wmm4
- Published
- Record updated
- Affected
- lfx-docling < 0.1.2, fixed in 0.1.2
- lfx < 1.10.3, fixed in 1.10.3
- langflow-base < 0.10.3, fixed in 0.10.3
- and 1 more
Summary
Before Langflow 1.10.3, several built-in components, including RSS Reader, SearXNG, Web Search, Home Assistant, Glean Search and Docling Serve, sent server-side requests to flow-author-controlled URLs with no SSRF enforcement. An authenticated user who can build or run flows could reach loopback, private, link-local and cloud metadata addresses and often read the response back through the component output.
Mitigation
Fixed in Langflow 1.10.3 (and 1.11.0+), with patched versions langflow 1.10.3, langflow-base 0.10.3, lfx 1.10.3 and lfx-docling 0.1.2. With default settings, outbound requests from these components are now validated after DNS resolution, pinned to the validated IP, and blocked for private, loopback, link-local or metadata addresses unless the operator allowlists the host.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- langflowPyPIReaches an LLM package through dependencies
- langflow-basePyPILLM dependency since 2024-04-01 · 1 tracked dependent
- lfxPyPILLM dependency since 2025-07-29 · 25 tracked dependents
- lfx-doclingPyPILLM dependency since 2026-09-11 · 1 tracked dependent
Related items
- LowAnthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection FlawsSimilar attack · The Hacker News
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading