Vulnerability index

Browse CVEs

115 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Langflow HIGH 7.1
CVE-2026-12945

IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on …

Fix: 1.10.2+
Fix from $1,950 2026-07-30
Langflow HIGH 7.1
CVE-2026-13442

IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only vector content and influence…

Fix: 1.10.2+
Fix from $1,950 2026-07-28
Langflow CRITICAL 9.8
CVE-2026-13446

IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound aut…

Fix: 1.10.2+
Fix from $2,300 2026-07-17
Langflow HIGH 8.1
CVE-2026-13445

IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read and modify another user's uploa…

Fix: 1.10.2+
Fix from $1,950 2026-07-17
Langflow CRITICAL 9.9
CVE-2026-8635

IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute a…

Fix: 1.10.1+
Fix from $2,300 2026-07-17
Langflow CRITICAL 9.9
CVE-2026-8859

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validat…

Fix: 1.10.1+
Fix from $2,300 2026-07-17
Langflow CRITICAL 9.8
CVE-2026-8505

IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the exec…

Fix: 1.10.1+
Fix from $2,300 2026-07-17
Langflow CRITICAL 9.9
CVE-2026-8476

IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache …

Fix: 1.10.1+
Fix from $2,300 2026-07-17
Langflow CRITICAL 9.9
CVE-2026-8481

IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/va…

Fix: 1.10.1+
Fix from $2,300 2026-07-17
Langflow HIGH 8.8
CVE-2026-7755

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcement on MCP server configuration…

Fix: 1.10.1+
Fix from $1,950 2026-07-17
Langflow HIGH 8.8
CVE-2026-8056

IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API. A critical security flaw ex…

Fix: 1.10.1+
Fix from $1,950 2026-07-17
Langflow HIGH 8.1
CVE-2026-7872

IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication…

Fix: 1.10.1+
Fix from $1,950 2026-07-17
Langflow HIGH 8.8
CVE-2026-7667

IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacker-controlled URL that returns…

Fix: 1.10.1+
Fix from $1,950 2026-07-17
Langflow MEDIUM 6.5
CVE-2026-7754

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure default configuration and incompl…

Fix: 1.10.1+
Fix from $1,600 2026-07-17
Langflow CRITICAL 9.8
CVE-2026-13448

IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the public flow build endpoint (…

Fix: 1.10.2+
Fix from $2,300 2026-07-17
Langflow HIGH 8.8
CVE-2026-14499

IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elevated privileges on the system…

Fix: 1.10.2+
Fix from $1,950 2026-07-17
Langflow CRITICAL 9.9
CVE-2026-9135

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulner…

Fix: 1.10.1+
Fix from $2,300 2026-07-17
Langflow CRITICAL 9.8
CVE-2026-9103

IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/a…

Fix: 1.10.1+
Fix from $2,300 2026-07-17
Langflow CRITICAL 9.8
CVE-2026-9198 KEVEPSS 17%

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) wit…

Fix: 1.10.1+
Fix from $2,300 2026-07-17
Langflow CRITICAL 9.8
CVE-2026-9202

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_A…

Fix: 1.10.1+
Fix from $2,300 2026-07-17
Langflow CRITICAL 9.9
CVE-2026-7873

IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive files including credentials,…

Fix: after 1.10.0
Fix from $2,300 2026-06-30
Langflow CRITICAL 9.8
CVE-2026-7663

IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due t…

Fix: 1.10.0+
Fix from $2,300 2026-06-30
Langflow CRITICAL 9.8
CVE-2026-7803

IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validation of flow nodes with missing or empty component t…

Fix: after 1.10.0
Fix from $2,300 2026-06-30
Langflow CRITICAL 9.8
CVE-2026-7871

IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all sec…

Fix: after 1.10.0
Fix from $2,300 2026-06-30
Langflow CRITICAL 9.1
CVE-2026-7874

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored credentials due to the use of a weak and reversible key derivatio…

Fix: after 1.10.0
Fix from $2,300 2026-06-30
Langflow CRITICAL 9.6
CVE-2026-10140

IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. A…

Fix: after 1.10.0
Fix from $2,300 2026-06-30
Langflow CRITICAL 9.1
CVE-2026-10560

IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoints that allows an unauthenti…

Fix: after 1.9.6
Fix from $2,300 2026-06-30
Langflow HIGH 8.2
CVE-2026-10564

IBM Langflow OSS 1.0.0 through 1.9.6 contains a Server-Side Request Forgery (SSRF). The legacy RSSReaderComponent in rss.py and SearXNG component in …

Fix: after 1.9.6
Fix from $1,950 2026-06-30
Langflow MEDIUM 6.5
CVE-2026-10546

IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the URL component ( src/lfx/src/lfx/components/da…

Fix: after 1.9.3
Fix from $1,600 2026-06-30
Langflow CRITICAL 10.0
CVE-2026-10134

IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversat…

Fix: after 1.9.3
Fix from $2,300 2026-06-30