Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.4
CVE-2026-5026
The '/api/v1/files/images/{flow_id}/{file_name}' endpoint serves SVG files with the 'image/svg+xml' content type without sanitizing their content.
S…
Langflow
Mitigation only
MEDIUM 5.3
CVE-2026-5022
The '/api/v1/files/images/{flow_id}/{file_name}' endpoint does not enforce any authentication or authorization checks, allowing any unauthenticated u…
Langflow
Mitigation only
HIGH 7.5
CVE-2026-33484EPSS 6%
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions 1.0.0 through 1.8.1, the `/api/v1/files/images/{flow_id}/{…
Langflow
1.9.0+
HIGH 7.5
CVE-2026-33497EPSS 20%
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.1, in the download_profile_picture function of th…
Langflow
1.7.1+
CRITICAL 9.1
CVE-2026-33475
Langflow is a tool for building and deploying AI-powered agents and workflows. An unauthenticated remote shell injection vulnerability exists in mult…
Langflow
1.9.0+
CRITICAL 9.9
CVE-2026-33309EPSS 11%
Langflow is a tool for building and deploying AI-powered agents and workflows. Versions 1.2.0 through 1.8.1 have a bypass of the patch for CVE-2025-6…
Langflow
1.9.0+
HIGH 8.8
CVE-2026-33053
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the delete_api_key_route() endpoint accept…
Langflow
1.9.0+
CRITICAL 9.8
CVE-2026-33017 KEVEPSS 96%
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id…
Langflow
1.8.2+
CRITICAL 9.8
CVE-2026-27966EPSS 34%
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent node in Langflow hardcodes `allo…
Langflow
1.8.0+
CRITICAL 9.8
CVE-2026-0770 KEVEPSS 57%
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote …
Langflow
after 1.7.3
HIGH 7.5
CVE-2026-0772
Langflow Disk Cache Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…
Langflow
Mitigation only
HIGH 7.1
CVE-2026-0771
Langflow PythonFunction Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on a…
Langflow
Mitigation only
CRITICAL 9.8
CVE-2026-0768
Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in…
Langflow
Mitigation only
CRITICAL 9.8
CVE-2026-0769EPSS 34%
Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitra…
Langflow
Mitigation only
CRITICAL 9.1
CVE-2026-21445EPSS 34%
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0.dev45, multiple critical API endpoints in Langf…
Langflow
1.7.1+
HIGH 7.1
CVE-2025-68478
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, if an arbitrary path is specified in the reque…
Langflow
1.7.0+
MEDIUM 6.5
CVE-2025-68477EPSS 6%
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, Langflow provides an API Request component tha…
Langflow
1.7.0+
HIGH 8.8
CVE-2025-34291 KEVEPSS 84%
Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permis…
Langflow
after 1.6.9
HIGH 8.8
CVE-2025-57760
Langflow is a tool for building and deploying AI-powered agents and workflows. A privilege escalation vulnerability exists in Langflow containers whe…
Langflow
1.5.0+
CRITICAL 9.8
CVE-2025-3248 KEVEPSS 100%
Langflow versions prior to 1.3.0 are susceptible to code injection in
the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can …
Langflow
1.3.0+
CRITICAL 9.8
CVE-2024-48061
langflow <=1.0.18 is vulnerable to Remote Code Execution (RCE) as any component provided the code functionality and the components run on the local m…
Langflow
after 1.0.18
CRITICAL 9.8
CVE-2024-42835
langflow v1.0.12 was discovered to contain a remote code execution (RCE) vulnerability via the PythonCodeTool component.
Langflow
No fix yet
MEDIUM 6.5
CVE-2024-9277
A vulnerability classified as problematic was found in Langflow up to 1.0.18. Affected by this vulnerability is an unknown functionality of the file …
Langflow
after 1.0.18
HIGH 8.8
CVE-2024-7297EPSS 21%
Langflow versions prior to 1.0.13 suffer from a Privilege Escalation vulnerability, allowing a remote and low privileged attacker to gain super admin…
Langflow
1.0.13+
CRITICAL 9.8
CVE-2024-37014EPSS 57%
Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and provide a …
Langflow
after 0.6.19