Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Langflow OSS — Vulnerabilities & Security Advisories 118

All 118 CVE vulnerabilities found in Langflow OSS, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with the open-source Langflow platform, specifically focusing on software weaknesses within its workflow orchestration engine. The collection encompasses a range of security flaws, including remote code execution risks, injection attacks, and improper access control issues, documented from the product's initial public release through the most recent advisory updates. Readers can utilize this resource to track vendor-issued security advisories, analyze the prevalence of specific weakness classes within low-code AI development tools, and review the complete vulnerability history for Langflow OSS to assess its current security posture. By centralizing these records, the page provides a structured view of how the project has addressed emerging threats over time. This aggregation supports security professionals, developers, and enterprise users in making informed decisions regarding the deployment of Langflow in production environments. The data reflects official disclosures and community-reported issues, offering a comprehensive timeline of identified risks without requiring users to navigate multiple disparate sources. Understanding the evolution of these vulnerabilities helps stakeholders evaluate the maturity of the project's security practices and identify potential gaps in their own implementations. This summary serves as a technical reference for assessing the risk profile of Langflow OSS, highlighting critical areas where additional hardening or monitoring may be required to mitigate known attack vectors.

Vendor: IBM

CVE ID Title CVSS Severity Published
CVE-2026-9130 Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement 7.1 High 2026-08-05
CVE-2026-10547 Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement CWE-284 5.9 Medium 2026-08-05
CVE-2026-7869 Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement CWE-22 5.4 Medium 2026-08-05
CVE-2026-8470 Langflow is affected by weaknesses in secret handling and sensitive configuration access CWE-327 7.4 High 2026-08-05
CVE-2026-9205 Langflow is affected by weaknesses in secret handling and sensitive configuration access CWE-338 7.4 High 2026-08-05
CVE-2026-10128 Langflow is affected by weaknesses in secret handling and sensitive configuration access CWE-200 6.5 Medium 2026-08-05
CVE-2026-9081 Langflow OSS is affected by server-side request forgery in provider validation and API request functionality CWE-918 7.1 High 2026-08-05
CVE-2026-7657 Langflow OSS is affected by server-side request forgery in provider validation and API request functionality CWE-918 6.5 Medium 2026-08-05
CVE-2026-17625 Langflow is affected by OS Command Injection in Model Context Protocol features CWE-78 7.2 High 2026-08-05
CVE-2026-17623 Langflow is affected OS Command Injection in Model Context Protocol features CWE-78 8.8 High 2026-08-05
CVE-2026-17630 Langflow is affected by security vulnerabilities in Model Context Protocol features CWE-184 7.2 High 2026-08-05
CVE-2026-17626 Langflow is affected by security vulnerabilities in Model Context Protocol features CWE-266 8.8 High 2026-08-05
CVE-2026-8446 Langflow is affected by security vulnerabilities in Model Context Protocol features CWE-306 7.5 High 2026-08-05
CVE-2026-7646 Langflow is affected by security vulnerabilities in Model Context Protocol features CWE-22 6.5 Medium 2026-08-05
CVE-2026-9077 Reliance on Untrusted Inputs in a Security Decision vulnerabilities in Model Context Protocol features CWE-807 8.5 High 2026-08-05
CVE-2026-12946 Remote Code Execution in CUGA Component CodeAgent CWE-94 9.9 Critical 2026-07-30
CVE-2026-13444 Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints CWE-520 - - 2026-07-30
CVE-2026-10700 Broken Access Control Vulnerabilities in Langflow 1.0.0 - 1.8.4 File Handling API Allowed Unauthorized Access to User Files CWE-639 6.5 Medium 2026-07-30
CVE-2026-13435 Python Interpreter Sandbox Bypass Leading to Sensitive Data Exposure CWE-94 9.9 Critical 2026-07-30
CVE-2026-12942 Langflow is affected by path traversal due to multiple unauthenticated and insufficiently authorized API endpoints CWE-22 7.5 High 2026-07-30
CVE-2026-12945 Langflow is affected by exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints CWE-639 7.1 High 2026-07-30
CVE-2026-12940 Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpoints CWE-78 9.8 Critical 2026-07-30
CVE-2026-13442 Langflow is affected by NET Misconfiguration: Use of Impersonation due to multiple unauthenticated and insufficiently authorized API endpoints CWE-520 7.1 High 2026-07-28
CVE-2026-13445 Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints CWE-639 8.1 High 2026-07-17
CVE-2026-13446 Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints CWE-798 9.8 Critical 2026-07-17
CVE-2026-13448 Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints 8.1 High 2026-07-17
CVE-2026-14499 Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints CWE-78 8.8 High 2026-07-17
CVE-2026-7667 Path Traversal Vulnerability in API Request Component Content-Disposition Header Processing CWE-22 8.8 High 2026-07-17
CVE-2026-7754 SSRF Protection Configuration Vulnerability 7.7 High 2026-07-17
CVE-2026-7755 MCP Server Configuration Validator Bypass via File Upload API 8.8 High 2026-07-17

All 118 known CVE vulnerabilities affecting Langflow OSS with full Chinese analysis, references, and POCs where available.