Vulnerability index

Browse CVEs

115 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-9205 IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function. Langflow 1.11.0+ Fix from $2,3002026-08-05 HIGH 8.8 CVE-2026-9196 IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to imp… Langflow 1.11.0+ Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-9201 IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in the custom c… Langflow 1.11.0+ Fix from $1,9502026-08-05 HIGH 7.1 CVE-2026-9130 IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access … Langflow 1.11.0+ Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-8478 IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input… Langflow 1.11.0+ Fix from $1,9502026-08-05 CRITICAL 9.1 CVE-2026-8470 IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random mod… Langflow 1.11.0+ Fix from $2,3002026-08-05 HIGH 8.8 CVE-2026-8182 IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any credentials via … Langflow 1.11.0+ Fix from $1,9502026-08-05 HIGH 7.7 CVE-2026-8183 IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10… Langflow 1.11.0+ Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-7658 IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path traversal sequences and bypass… Langflow 1.11.0+ Fix from $1,6002026-08-05 MEDIUM 5.4 CVE-2026-7869 IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledge_bases`). This occurs becaus… Langflow 1.11.0+ Fix from $1,6002026-08-05 HIGH 8.8 CVE-2026-17633 IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injection. Langflow 1.11.0+ Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-17632 IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code… Langflow 1.11.0+ Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-17624 IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, … Langflow 1.11.0+ Fix from $1,9502026-08-05 HIGH 8.1 CVE-2026-10547 IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/vertices endpoint, allowing… Langflow 1.11.0+ Fix from $1,9502026-08-05 HIGH 7.1 CVE-2026-9081 IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the validate_model_pro… Langflow 1.11.0+ Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-7657 IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplete and ineffective SSRF protection enfor… Langflow 1.11.0+ Fix from $1,6002026-08-05 HIGH 8.8 CVE-2026-17625 IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, … Langflow 1.11.0+ Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-10128 IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbitrary server environment varia… Langflow 1.11.0+ Fix from $1,6002026-08-05 HIGH 8.5 CVE-2026-9077 IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP se… Langflow 1.11.0+ Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-8446 IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP) composer endpoint when mcp_c… Langflow 1.11.0+ Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-7646 IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other users' uploaded documents, the… Langflow 1.11.0+ Fix from $1,6002026-08-05 HIGH 8.8 CVE-2026-17623 IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of the com… Langflow 1.11.0+ Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-17626 IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Docker-based… Langflow 1.11.0+ Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-17630 IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper validation of configuration parameters. Langflow 1.11.0+ Fix from $1,9502026-08-05 CRITICAL 9.9 CVE-2026-12946 IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input… Langflow 1.10.1+ Fix from $2,3002026-07-30 CRITICAL 9.9 CVE-2026-13435 IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation. Langflow 1.10.2+ Fix from $2,3002026-07-30 HIGH 8.1 CVE-2026-13444 IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents by creating their own flow with matchin… Langflow 1.10.2+ Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-12942 IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted… Langflow 1.10.2+ Fix from $1,9502026-07-30 MEDIUM 6.5 CVE-2026-10700 IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API that allow unauthorized access … Langflow 1.9.0+ Fix from $1,6002026-07-30 CRITICAL 9.8 CVE-2026-12940 IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model C… Langflow 1.10.2+ Fix from $2,3002026-07-30