Vulnerability index

Browse CVEs

115 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.1 CVE-2026-12945 IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on … Langflow 1.10.2+ Fix from $1,9502026-07-30 HIGH 7.1 CVE-2026-13442 IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only vector content and influence… Langflow 1.10.2+ Fix from $1,9502026-07-28 CRITICAL 9.8 CVE-2026-13446 IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound aut… Langflow 1.10.2+ Fix from $2,3002026-07-17 HIGH 8.1 CVE-2026-13445 IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read and modify another user's uploa… Langflow 1.10.2+ Fix from $1,9502026-07-17 CRITICAL 9.9 CVE-2026-8635 IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute a… Langflow 1.10.1+ Fix from $2,3002026-07-17 CRITICAL 9.9 CVE-2026-8859 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validat… Langflow 1.10.1+ Fix from $2,3002026-07-17 CRITICAL 9.8 CVE-2026-8505 IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the exec… Langflow 1.10.1+ Fix from $2,3002026-07-17 CRITICAL 9.9 CVE-2026-8476 IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache … Langflow 1.10.1+ Fix from $2,3002026-07-17 CRITICAL 9.9 CVE-2026-8481 IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/va… Langflow 1.10.1+ Fix from $2,3002026-07-17 HIGH 8.8 CVE-2026-7755 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcement on MCP server configuration… Langflow 1.10.1+ Fix from $1,9502026-07-17 HIGH 8.8 CVE-2026-8056 IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API. A critical security flaw ex… Langflow 1.10.1+ Fix from $1,9502026-07-17 HIGH 8.1 CVE-2026-7872 IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication… Langflow 1.10.1+ Fix from $1,9502026-07-17 HIGH 8.8 CVE-2026-7667 IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacker-controlled URL that returns… Langflow 1.10.1+ Fix from $1,9502026-07-17 MEDIUM 6.5 CVE-2026-7754 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure default configuration and incompl… Langflow 1.10.1+ Fix from $1,6002026-07-17 CRITICAL 9.8 CVE-2026-13448 IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the public flow build endpoint (… Langflow 1.10.2+ Fix from $2,3002026-07-17 HIGH 8.8 CVE-2026-14499 IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elevated privileges on the system… Langflow 1.10.2+ Fix from $1,9502026-07-17 CRITICAL 9.9 CVE-2026-9135 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulner… Langflow 1.10.1+ Fix from $2,3002026-07-17 CRITICAL 9.8 CVE-2026-9103 IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/a… Langflow 1.10.1+ Fix from $2,3002026-07-17 CRITICAL 9.8 CVE-2026-9198 KEVEPSS 17% IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) wit… Langflow 1.10.1+ Fix from $2,3002026-07-17 CRITICAL 9.8 CVE-2026-9202 IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_A… Langflow 1.10.1+ Fix from $2,3002026-07-17 CRITICAL 9.9 CVE-2026-7873 IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive files including credentials,… Langflow after 1.10.0 Fix from $2,3002026-06-30 CRITICAL 9.8 CVE-2026-7663 IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due t… Langflow 1.10.0+ Fix from $2,3002026-06-30 CRITICAL 9.8 CVE-2026-7803 IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validation of flow nodes with missing or empty component t… Langflow after 1.10.0 Fix from $2,3002026-06-30 CRITICAL 9.8 CVE-2026-7871 IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all sec… Langflow after 1.10.0 Fix from $2,3002026-06-30 CRITICAL 9.1 CVE-2026-7874 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored credentials due to the use of a weak and reversible key derivatio… Langflow after 1.10.0 Fix from $2,3002026-06-30 CRITICAL 9.6 CVE-2026-10140 IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. A… Langflow after 1.10.0 Fix from $2,3002026-06-30 CRITICAL 9.1 CVE-2026-10560 IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoints that allows an unauthenti… Langflow after 1.9.6 Fix from $2,3002026-06-30 HIGH 8.2 CVE-2026-10564 IBM Langflow OSS 1.0.0 through 1.9.6 contains a Server-Side Request Forgery (SSRF). The legacy RSSReaderComponent in rss.py and SearXNG component in … Langflow after 1.9.6 Fix from $1,9502026-06-30 MEDIUM 6.5 CVE-2026-10546 IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the URL component ( src/lfx/src/lfx/components/da… Langflow after 1.9.3 Fix from $1,6002026-06-30 CRITICAL 10.0 CVE-2026-10134 IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversat… Langflow after 1.9.3 Fix from $2,3002026-06-30