Loading
A Python package with a built-in web application
Declares an LLM dependency since 2024-04-01 (version 0.0.13).
Advisories that name langflow-base as affected. Advisory records do not state an ecosystem, so packages with the same name in other ecosystems also match. For a version-exact check of your own dependencies, use Stack Check.
| Advisory | Severity | Affected | Fixed in | Published |
|---|---|---|---|---|
| GHSA-j8f7-x8jm-wmm4: Langflow: SSRF in URL-taking components (protection disabled by default / warn-only, not applied to RSS, SearXNG, Web Search, Home Assistant, Glean, Docling) | Medium | < 0.10.3 | 0.10.3 | 2026-10-06 |
| CVE-2026-34046GHSA-8c4j-f57c-35cf: Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check | High | <= 0.5.0 | 0.5.1 | 2026-03-27 |
As declared in PyPI metadata for version 1.12.5. Optional extras are listed with their extra name.
Among the packages in the registry; not every dependent on PyPI.