Vulnerability index

Browse CVEs

115 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Langflow HIGH 8.5
CVE-2026-10129

IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) protection bypass vulnerability in the API Request component. An a…

Fix: after 1.9.3
Fix from $1,950 2026-06-30
Langflow CRITICAL 9.6
CVE-2026-55447

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling a files that are digested into the RAG,…

Fix: 1.9.2+
Fix from $2,300 2026-06-23
Langflow CRITICAL 9.3
CVE-2026-55450EPSS 12%

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can upload any amount of data to…

Fix: 1.9.1+
Fix from $2,300 2026-06-23
Langflow HIGH 8.4
CVE-2026-55255 KEVEPSS 29%

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerabili…

Fix: 1.9.1+
Fix from $1,950 2026-06-23
Langflow HIGH 7.5
CVE-2026-55446

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.0.19, an attacker can send a /api/v1/files/upload/ request …

Fix: 1.0.19+
Fix from $1,950 2026-06-23
Langflow MEDIUM 6.1
CVE-2026-55423

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.7.0, the logout button does not clear the session. The prev…

Fix: 1.7.0+
Fix from $1,600 2026-06-23
Langflow CRITICAL 9.6
CVE-2026-48519

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, the "Shareable Playground" (or "Public Flows" in code)…

Fix: 1.9.2+
Fix from $2,300 2026-06-23
Langflow MEDIUM 6.1
CVE-2026-48520

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.10.0, the "Shareable Playground" (or "Public Flows" in code…

Fix: 1.10.0+
Fix from $1,600 2026-06-23
Langflow MEDIUM 6.5
CVE-2026-42867

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowle…

Fix: 1.9.0+
Fix from $1,600 2026-06-23
Langflow HIGH 8.8
CVE-2026-33760

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow's /api/v1/monitor router exposes 7 endpoints …

Fix: 1.9.0+
Fix from $1,950 2026-06-23
Langflow CRITICAL 9.8
CVE-2026-7664

IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due t…

Fix: after 1.8.4
Fix from $2,300 2026-06-22
Langflow CRITICAL 10.0
CVE-2026-10561

IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass tha…

Fix: after 1.9.3
Fix from $2,300 2026-06-22
Langflow HIGH 7.8
CVE-2026-12822

A vulnerability was identified in langflow-ai langflow up to 1.9.3. This affects an unknown function of the component Bundle URL Loader. The manipula…

Fix: 1.9.3+
Fix from $1,950 2026-06-22
Langflow HIGH 8.1
CVE-2026-7787

IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information by bypassing authentication using inse…

Fix: 1.9.2+
Fix from $1,950 2026-06-11
Langflow Desktop MEDIUM 5.4
CVE-2026-3341

IBM Langflow Desktop 1.0.0 through 1.9.2 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker t…

Fix: 1.9.3+
Fix from $1,600 2026-06-11
Langflow CRITICAL 9.8
CVE-2026-7524

IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links during archive extraction.

Fix: after 1.9.1
Fix from $2,300 2026-05-27
Langflow HIGH 7.5
CVE-2026-7528

IBM Langflow OSS 1.0.0 through 1.9.0 could allow a denial of service due to uncontrolled resource consumption.

Fix: after 1.9.0
Fix from $1,950 2026-05-27
Langflow CRITICAL 9.6
CVE-2026-42048

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowle…

Fix: 1.9.0+
Fix from $2,300 2026-05-12
Langflow Desktop HIGH 8.8
CVE-2026-6543

IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow allows an attacker to execute arbitrary commands with the privileges of the process running Langflo…

Fix: after 1.8.4
Fix from $1,950 2026-04-30
Langflow HIGH 8.1
CVE-2026-6542

IBM Langflow OSS 1.0.0 through 1.8.4 could allow any user to supply a flow_id to read transaction logs and vertex build data belonging to other users…

Fix: 1.9.0+
Fix from $1,950 2026-04-30
Langflow Desktop MEDIUM 6.5
CVE-2026-3345

IBM Langflow Desktop <=1.8.4 Langflow could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted…

Fix: after 1.8.4
Fix from $1,600 2026-04-30
Langflow Desktop HIGH 7.5
CVE-2026-4503

IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow could allow an unauthenticated user to view other users' images due to an indirect object reference…

Fix: after 1.8.4
Fix from $1,950 2026-04-30
Langflow Desktop MEDIUM 6.5
CVE-2026-4502

IBM Langflow Desktop 1.2.0 through 1.8.4 Langflow could allow an authenticated attacker to traverse directories on the system. An attacker could send…

Fix: after 1.8.4
Fix from $1,600 2026-04-30
Langflow Desktop MEDIUM 6.5
CVE-2026-3340

IBM Langflow Desktop 1.0.0 through 1.8.4 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker t…

Fix: after 1.8.4
Fix from $1,600 2026-04-30
Langflow Desktop MEDIUM 6.4
CVE-2026-3346

IBM Langflow Desktop 1.6.0 through 1.8.4 Lanflow is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to emb…

Fix: after 1.8.4
Fix from $1,600 2026-04-30
Langflow HIGH 8.8
CVE-2026-3357

IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, caused by an insecure de…

Fix: 1.8.3+
Fix from $1,950 2026-04-08
Langflow Base HIGH 8.8
CVE-2026-34046

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.5.1, the `_read_flow` helper in `src/backend/base/l…

Fix: 0.5.1 / 1.5.0+
Fix from $1,950 2026-03-27
Langflow CRITICAL 9.9
CVE-2026-33873

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.9.0, the Agentic Assistant feature in Langflow exec…

Fix: 1.9.0+
Fix from $2,300 2026-03-27
Langflow HIGH 8.8
CVE-2026-5027EPSS 31%

The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arb…

Mitigation only
Fix from $1,950 2026-03-27
Langflow MEDIUM 6.5
CVE-2026-5025

The '/logs' and '/logs-stream' endpoints in the log router allow any authenticated user to read the full application log buffer. These endpoints only…

Mitigation only
Fix from $1,600 2026-03-27