Skip to content

langflow

A Python package with a built-in web application

Does not declare an LLM SDK itself, but depends on a package that does, 1 step away.

PyPILatest 1.12.5First release 2023-03-14Registry pageRepositoryChecked 2026-10-09

Advisories

Advisories that name langflow as affected. Advisory records do not state an ecosystem, so packages with the same name in other ecosystems also match. For a version-exact check of your own dependencies, use Stack Check.

AdvisorySeverityAffectedFixed inPublished
GHSA-j8f7-x8jm-wmm4: Langflow: SSRF in URL-taking components (protection disabled by default / warn-only, not applied to RSS, SearXNG, Web Search, Home Assistant, Glean, Docling)Medium< 1.10.31.10.32026-10-06
CVE-2026-10561GHSA-8qpj-27x8-pwpq: Langflow: PythonREPLComponent executes unsandboxed Python code, enabling authenticated RCE and privilege escalationCritical< 1.10.11.10.12026-10-06
CVE-2026-55447GHSA-ccv6-r384-xp75: Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploitCritical< 1.9.21.9.22026-06-19
CVE-2026-55446GHSA-qwqc-p3q8-wcg9: Langflow: Unauthenticated DoS through multipart form boundary file uploadHigh< 1.0.191.0.192026-06-19
CVE-2026-55423GHSA-7hw8-6q6r-4276: Langflow: Logout button does not clear sessionMedium< 1.7.01.7.12026-06-19
CVE-2026-55255GHSA-qrpv-q767-xqq2: Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's FlowCritical< 1.9.11.9.12026-06-19
CVE-2026-55450GHSA-x223-p2gf-v735: Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leakCritical< 1.9.11.9.12026-06-17
CVE-2026-48520GHSA-rcjh-r59h-gq37: Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file readMedium< 1.10.01.10.02026-06-16
CVE-2026-48519GHSA-v5ff-9q35-q26f: Langflow: Unauthenticated RCE in Shareable PlaygroundsCritical<= 1.9.11.9.22026-06-16
CVE-2026-42867GHSA-79ph-745m-6wxq: Langflow: Path Traversal in Knowledge Bases API via Creation EndpointMedium<= 1.8.41.9.02026-06-16
CVE-2026-33760GHSA-9c59-2mvc-vfr8: Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints High< 1.9.01.9.02026-06-16
CVE-2026-34046GHSA-8c4j-f57c-35cf: Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership CheckHigh<= 1.5.01.5.12026-03-27
CVE-2026-33497GHSA-ph9w-r52h-28p7: langflow: /profile_pictures/{folder_name}/{file_name} endpoint file readingHigh< 1.7.11.7.12026-03-20
CVE-2026-33484GHSA-7grx-3xcx-2xv5: langflow has Unauthenticated IDOR on Image DownloadsHigh>= 1.0.0, <= 1.8.12026-03-20
CVE-2026-33309GHSA-g2j9-7rj2-gm6c: Langflow has an Arbitrary File Write (RCE) via v2 APICritical>= 1.2.0, <= 1.8.11.9.02026-03-19
CVE-2026-33053GHSA-rf6x-r45m-xv3w: Langflow is Missing Ownership Verification in API Key Deletion (IDOR)High< 1.7.21.7.22026-03-18
CVE-2026-33017GHSA-vwmf-pq79-vjvx: Unauthenticated Remote Code Execution in Langflow via Public Flow Build EndpointCritical<= 1.8.12026-03-17

How it reaches an LLM package

Shortest path through the runtime dependencies of each latest release.

  1. langflow
  2. langflow-base

Dependencies of the latest release

As declared in PyPI metadata for version 1.12.5. Optional extras are listed with their extra name.