Vulnerability index

Browse CVEs

9 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Langflow HIGH 8.8
CVE-2026-5027EPSS 31%

The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arb…

Mitigation only
Fix from $1,950 2026-03-27
Langflow MEDIUM 6.5
CVE-2026-5025

The '/logs' and '/logs-stream' endpoints in the log router allow any authenticated user to read the full application log buffer. These endpoints only…

Mitigation only
Fix from $1,600 2026-03-27
Langflow MEDIUM 5.4
CVE-2026-5026

The '/api/v1/files/images/{flow_id}/{file_name}' endpoint serves SVG files with the 'image/svg+xml' content type without sanitizing their content. S…

Mitigation only
Fix from $1,600 2026-03-27
Langflow MEDIUM 5.3
CVE-2026-5022

The '/api/v1/files/images/{flow_id}/{file_name}' endpoint does not enforce any authentication or authorization checks, allowing any unauthenticated u…

Mitigation only
Fix from $1,600 2026-03-27
Langflow HIGH 7.5
CVE-2026-0772

Langflow Disk Cache Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…

Mitigation only
Fix from $1,950 2026-01-23
Langflow HIGH 7.1
CVE-2026-0771

Langflow PythonFunction Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on a…

Mitigation only
Fix from $1,950 2026-01-23
Langflow CRITICAL 9.8
CVE-2026-0768

Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in…

Mitigation only
Fix from $2,300 2026-01-23
Langflow CRITICAL 9.8
CVE-2026-0769EPSS 34%

Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitra…

Mitigation only
Fix from $2,300 2026-01-23
Langflow CRITICAL 9.8
CVE-2024-42835

langflow v1.0.12 was discovered to contain a remote code execution (RCE) vulnerability via the PythonCodeTool component.

No fix yet
Fix from $2,300 2024-10-31