Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Langflow OSS — Vulnerabilities & Security Advisories 118

All 118 CVE vulnerabilities found in Langflow OSS, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with the open-source Langflow platform, specifically focusing on software weaknesses within its workflow orchestration engine. The collection encompasses a range of security flaws, including remote code execution risks, injection attacks, and improper access control issues, documented from the product's initial public release through the most recent advisory updates. Readers can utilize this resource to track vendor-issued security advisories, analyze the prevalence of specific weakness classes within low-code AI development tools, and review the complete vulnerability history for Langflow OSS to assess its current security posture. By centralizing these records, the page provides a structured view of how the project has addressed emerging threats over time. This aggregation supports security professionals, developers, and enterprise users in making informed decisions regarding the deployment of Langflow in production environments. The data reflects official disclosures and community-reported issues, offering a comprehensive timeline of identified risks without requiring users to navigate multiple disparate sources. Understanding the evolution of these vulnerabilities helps stakeholders evaluate the maturity of the project's security practices and identify potential gaps in their own implementations. This summary serves as a technical reference for assessing the risk profile of Langflow OSS, highlighting critical areas where additional hardening or monitoring may be required to mitigate known attack vectors.

Vendor: IBM

CVE ID Title CVSS Severity Published
CVE-2026-19301 Langflow is vulnerable to Server-Side Request Forgery due to missing or bypassable URL validation in multiple components CWE-918 5.0 Medium 2026-09-04
CVE-2026-19303 Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing components CWE-22 8.1 High 2026-09-04
CVE-2026-19300 Langflow is vulnerable to information disclosure due to cross-user MCP tool cache collision and incomplete secret scrubbing on public flows CWE-200 7.5 High 2026-09-04
CVE-2026-19299 Langflow is vulnerable to arbitrary local file read due to path traversal in ChatInput, bundle FileInput, and GitExtractor components CWE-22 6.5 Medium 2026-09-04
CVE-2026-19302 Langflow is vulnerable to arbitrary local file read due to path traversal in ChatInput, bundle FileInput, and GitExtractor components CWE-22 6.5 Medium 2026-09-04
CVE-2026-19304 Langflow is vulnerable to Server-Side Request Forgery due to missing or bypassable URL validation in multiple components CWE-918 7.7 High 2026-09-04
CVE-2026-19305 Langflow is vulnerable to Server-Side Request Forgery due to missing or bypassable URL validation in multiple components CWE-918 8.6 High 2026-09-04
CVE-2026-19306 Langflow is vulnerable to arbitrary local file read due to path traversal in ChatInput, bundle FileInput, and GitExtractor components CWE-22 7.7 High 2026-09-04
CVE-2026-9138 Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing components CWE-22 6.5 Medium 2026-09-04
CVE-2026-8447 Langflow is vulnerable to stored cross-site scripting and IP spoofing due to unsanitized Markdown rendering and untrusted proxy header trust CWE-79 6.1 Medium 2026-09-04
CVE-2026-9186 Langflow is vulnerable to stored cross-site scripting and IP spoofing due to unsanitized Markdown rendering and untrusted proxy header trust CWE-284 6.5 Medium 2026-09-04
CVE-2026-19295 Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement CWE-95 9.9 Critical 2026-08-28
CVE-2026-19294 Langflow is affected by multiple authentication bypass, path traversal, authorization, and server-side request forgery vulnerabilities CWE-639 6.4 Medium 2026-08-28
CVE-2026-19286 Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement CWE-94 9.8 Critical 2026-08-28
CVE-2026-18904 Langflow is affected by multiple authentication bypass, path traversal, authorization, and server-side request forgery vulnerabilities CWE-639 8.2 High 2026-08-28
CVE-2026-18899 Langflow is affected by multiple authentication bypass, path traversal, authorization, and server-side request forgery vulnerabilities CWE-22 7.5 High 2026-08-28
CVE-2026-18891 Langflow is affected by multiple authentication bypass, path traversal, authorization, and server-side request forgery vulnerabilities CWE-287 8.2 High 2026-08-28
CVE-2026-18729 Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement CWE-94 8.8 High 2026-08-28
CVE-2026-18545 Langflow is affected by multiple authentication bypass, path traversal, authorization, and server-side request forgery vulnerabilities CWE-918 4.3 Medium 2026-08-28
CVE-2026-19875 Unauthenticated Registration POST Endpoint Permits Admin Email Overwrite and Outbound Relay Abuse in Langflow CWE-306 7.5 High 2026-08-19
CVE-2026-19297 Insufficient Authentication Brute Force Protection on Login Endpoint CWE-307 9.1 Critical 2026-08-13
CVE-2026-17624 Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling CWE-94 8.5 High 2026-08-05
CVE-2026-17633 Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling CWE-94 8.5 High 2026-08-05
CVE-2026-17632 Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling CWE-94 8.8 High 2026-08-05
CVE-2026-9196 Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling CWE-94 8.1 High 2026-08-05
CVE-2026-8182 Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling CWE-94 8.8 High 2026-08-05
CVE-2026-9201 Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling CWE-326 8.8 High 2026-08-05
CVE-2026-8478 Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling CWE-94 8.8 High 2026-08-05
CVE-2026-8183 Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement CWE-22 7.7 High 2026-08-05
CVE-2026-7658 Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement CWE-22 6.5 Medium 2026-08-05

All 118 known CVE vulnerabilities affecting Langflow OSS with full Chinese analysis, references, and POCs where available.