Langflow 是一款用于构建和部署 AI 驱动的智能体(agents)和工作流的工具。在版本 1.0.0 至 1.10.1 期间,Langflow 未在已弃用的 API 端点 和 中验证流程(flow)的所有权。 在版本 1.7.1 及更早版本中,未经身份验证的攻击者只要知道其他用户的流程 UUID,即可访问上述端点;从版本 1.7.2 至 1.10.0 开始,调用者虽需进行身份验证,但无需具备特殊权限。通过此类访问,攻击者可以调用 来加载并缓存私有流程图,枚举其节点(vertex)标识符,并利用 执行选定的节
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| langflow-ai | langflow | >= 1.0.0, < 1.10.1 | - |
|
| langflow-ai | langflow-base | < 0.10.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105697 | 9.9 CRITICAL | Langflow: OS command injection (RCE) via arbitrary command in MCP stdio server configurati |
| CVE-2026-105740 | 9.9 CRITICAL | Langflow: Authenticated RCE via MCP Stdio transport allows any user to execute arbitrary O |
| CVE-2026-105699 | 7.1 HIGH | Langflow: Authenticated Cross-Project File Disclosure via Unscoped MCP Resource Handlers |
| CVE-2026-105741 | 7.1 HIGH | Langflow: IP Spoofing Bypass via `X-Forwarded-For` Allowing Remote Configuration Write |
No comments yet