Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Langflow OSS — Vulnerabilities & Security Advisories 118

All 118 CVE vulnerabilities found in Langflow OSS, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with the open-source Langflow platform, specifically focusing on software weaknesses within its workflow orchestration engine. The collection encompasses a range of security flaws, including remote code execution risks, injection attacks, and improper access control issues, documented from the product's initial public release through the most recent advisory updates. Readers can utilize this resource to track vendor-issued security advisories, analyze the prevalence of specific weakness classes within low-code AI development tools, and review the complete vulnerability history for Langflow OSS to assess its current security posture. By centralizing these records, the page provides a structured view of how the project has addressed emerging threats over time. This aggregation supports security professionals, developers, and enterprise users in making informed decisions regarding the deployment of Langflow in production environments. The data reflects official disclosures and community-reported issues, offering a comprehensive timeline of identified risks without requiring users to navigate multiple disparate sources. Understanding the evolution of these vulnerabilities helps stakeholders evaluate the maturity of the project's security practices and identify potential gaps in their own implementations. This summary serves as a technical reference for assessing the risk profile of Langflow OSS, highlighting critical areas where additional hardening or monitoring may be required to mitigate known attack vectors.

Vendor: IBM

CVE ID Title CVSS Severity Published
CVE-2026-12944 Incomplete Security Scanner Blocklist Enables Network-Based Code Execution CWE-918 9.6 Critical 2026-09-14
CVE-2026-12763 Langflow is vulnerable to authentication bypass and insufficient session expiration CWE-306 4.2 Medium 2026-09-14
CVE-2026-12765 Langflow OSS is affected by server-side request forgery due to missing URL validation in flow components CWE-918 6.5 Medium 2026-09-14
CVE-2026-12766 Langflow is vulnerable to Server-Side Request Forgery due to missing or bypassable URL validation in multiple components CWE-918 5.4 Medium 2026-09-14
CVE-2026-12767 Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches CWE-918 6.5 Medium 2026-09-14
CVE-2026-17628 Langflow is affected by improper authentication due to missing password verification in the password reset endpoint CWE-287 5.4 Medium 2026-09-14
CVE-2026-76059 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards CWE-693 8.8 High 2026-09-10
CVE-2026-78569 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards CWE-78 8.8 High 2026-09-10
CVE-2026-78571 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards CWE-94 8.8 High 2026-09-10
CVE-2026-78575 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards CWE-78 8.8 High 2026-09-10
CVE-2026-79723 Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches CWE-918 5.0 Medium 2026-09-10
CVE-2026-79724 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards CWE-78 9.8 Critical 2026-09-10
CVE-2026-79725 Langflow is vulnerable to unauthorized file system access due to path traversal and missing storage path validation CWE-284 6.5 Medium 2026-09-10
CVE-2026-79742 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards CWE-94 8.8 High 2026-09-10
CVE-2026-81204 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards CWE-94 9.8 Critical 2026-09-10
CVE-2026-81211 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards CWE-862 8.8 High 2026-09-10
CVE-2026-81941 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards CWE-284 8.8 High 2026-09-10
CVE-2026-81213 Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches CWE-918 8.6 High 2026-09-10
CVE-2026-81265 Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches CWE-918 7.5 High 2026-09-10
CVE-2026-81268 Langflow is vulnerable to authentication bypass and insufficient session expiration CWE-613 8.1 High 2026-09-10
CVE-2026-81940 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards CWE-94 8.8 High 2026-09-10
CVE-2026-84889 A path traversal vulnerability in file handling components could allow an authenticated attacker to write files to arbitrary locations on the server filesystem CWE-22 8.8 High 2026-09-10
CVE-2026-85025 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards CWE-863 9.8 Critical 2026-09-10
CVE-2026-9225 Langflow is vulnerable to unauthorized file system access due to path traversal and missing storage path validation CWE-639 6.5 Medium 2026-09-10
CVE-2026-14470 Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base components CWE-22 6.5 Medium 2026-09-04
CVE-2026-17627 Langflow is affected by improper authorization due to missing access control on the voice-mode WebSocket endpoint CWE-639 4.9 Medium 2026-09-04
CVE-2026-17621 Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base components CWE-22 5.4 Medium 2026-09-04
CVE-2026-17622 Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base components CWE-22 6.5 Medium 2026-09-04
CVE-2026-17631 Langflow OSS is affected by server-side request forgery due to missing URL validation in flow components CWE-918 5.0 Medium 2026-09-04
CVE-2026-19298 Langflow is vulnerable to remote code execution due to authorization policy bypass in the authenticated flow-build endpoint CWE-94 8.8 High 2026-09-04

All 118 known CVE vulnerabilities affecting Langflow OSS with full Chinese analysis, references, and POCs where available.