Vulnerability index

Browse CVEs

115 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Langflow CRITICAL 9.8
CVE-2026-9205

IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.

Fix: 1.11.0+
Fix from $2,300 2026-08-05
Langflow HIGH 8.8
CVE-2026-9196

IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to imp…

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow HIGH 8.8
CVE-2026-9201

IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in the custom c…

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow HIGH 7.1
CVE-2026-9130

IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access …

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow HIGH 8.8
CVE-2026-8478

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input…

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow CRITICAL 9.1
CVE-2026-8470

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random mod…

Fix: 1.11.0+
Fix from $2,300 2026-08-05
Langflow HIGH 8.8
CVE-2026-8182

IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any credentials via …

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow HIGH 7.7
CVE-2026-8183

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10…

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow MEDIUM 6.5
CVE-2026-7658

IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path traversal sequences and bypass…

Fix: 1.11.0+
Fix from $1,600 2026-08-05
Langflow MEDIUM 5.4
CVE-2026-7869

IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledge_bases`). This occurs becaus…

Fix: 1.11.0+
Fix from $1,600 2026-08-05
Langflow HIGH 8.8
CVE-2026-17633

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injection.

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow HIGH 8.8
CVE-2026-17632

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code…

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow HIGH 8.8
CVE-2026-17624

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, …

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow HIGH 8.1
CVE-2026-10547

IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/vertices endpoint, allowing…

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow HIGH 7.1
CVE-2026-9081

IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the validate_model_pro…

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow MEDIUM 6.5
CVE-2026-7657

IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplete and ineffective SSRF protection enfor…

Fix: 1.11.0+
Fix from $1,600 2026-08-05
Langflow HIGH 8.8
CVE-2026-17625

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, …

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow MEDIUM 6.5
CVE-2026-10128

IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbitrary server environment varia…

Fix: 1.11.0+
Fix from $1,600 2026-08-05
Langflow HIGH 8.5
CVE-2026-9077

IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP se…

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow HIGH 7.5
CVE-2026-8446

IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP) composer endpoint when mcp_c…

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow MEDIUM 6.5
CVE-2026-7646

IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other users' uploaded documents, the…

Fix: 1.11.0+
Fix from $1,600 2026-08-05
Langflow HIGH 8.8
CVE-2026-17623

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of the com…

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow HIGH 8.8
CVE-2026-17626

IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Docker-based…

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow HIGH 8.8
CVE-2026-17630

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper validation of configuration parameters.

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow CRITICAL 9.9
CVE-2026-12946

IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input…

Fix: 1.10.1+
Fix from $2,300 2026-07-30
Langflow CRITICAL 9.9
CVE-2026-13435

IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation.

Fix: 1.10.2+
Fix from $2,300 2026-07-30
Langflow HIGH 8.1
CVE-2026-13444

IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents by creating their own flow with matchin…

Fix: 1.10.2+
Fix from $1,950 2026-07-30
Langflow HIGH 7.5
CVE-2026-12942

IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted…

Fix: 1.10.2+
Fix from $1,950 2026-07-30
Langflow MEDIUM 6.5
CVE-2026-10700

IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API that allow unauthorized access …

Fix: 1.9.0+
Fix from $1,600 2026-07-30
Langflow CRITICAL 9.8
CVE-2026-12940

IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model C…

Fix: 1.10.2+
Fix from $2,300 2026-07-30