Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Langflow OSS — Vulnerabilities & Security Advisories 118

All 118 CVE vulnerabilities found in Langflow OSS, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with the open-source Langflow platform, specifically focusing on software weaknesses within its workflow orchestration engine. The collection encompasses a range of security flaws, including remote code execution risks, injection attacks, and improper access control issues, documented from the product's initial public release through the most recent advisory updates. Readers can utilize this resource to track vendor-issued security advisories, analyze the prevalence of specific weakness classes within low-code AI development tools, and review the complete vulnerability history for Langflow OSS to assess its current security posture. By centralizing these records, the page provides a structured view of how the project has addressed emerging threats over time. This aggregation supports security professionals, developers, and enterprise users in making informed decisions regarding the deployment of Langflow in production environments. The data reflects official disclosures and community-reported issues, offering a comprehensive timeline of identified risks without requiring users to navigate multiple disparate sources. Understanding the evolution of these vulnerabilities helps stakeholders evaluate the maturity of the project's security practices and identify potential gaps in their own implementations. This summary serves as a technical reference for assessing the risk profile of Langflow OSS, highlighting critical areas where additional hardening or monitoring may be required to mitigate known attack vectors.

Vendor: IBM

CVE ID Title CVSS Severity Published
CVE-2026-7872 Path Traversal Vulnerability in File Component Leading to Arbitrary File Read and Authentication Bypass CWE-22 7.5 High 2026-07-17
CVE-2026-8056 Parameter Injection Vulnerability in API Graph Execution Engine CWE-94 8.8 High 2026-07-17
CVE-2026-8476 Disk Cache Deserialization Remote Code Execution Vulnerability CWE-502 9.9 Critical 2026-07-17
CVE-2026-8481 Remote Code Execution via Code Validation Endpoint CWE-94 9.9 Critical 2026-07-17
CVE-2026-8505 Authentication Bypass in Webhook Endpoints Allowed Unauthorized Flow Execution 9.8 Critical 2026-07-17
CVE-2026-8635 Arbitrary Code Execution in Python Interpreter Component CWE-94 9.9 Critical 2026-07-17
CVE-2026-8859 Path Traversal in APIRequest Component via Content-Disposition Header CWE-22 9.9 Critical 2026-07-17
CVE-2026-9103 Unauthenticated Superuser Token Issuance via Auto-Login Endpoint CWE-306 9.8 Critical 2026-07-17
CVE-2026-9135 Policies Component Dynamic CodeInput Fields Bypass Custom Component Validation CWE-94 9.9 Critical 2026-07-17
CVE-2026-9198 Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation CWE-94 9.8 Critical 2026-07-17
CVE-2026-9202 Unauthenticated User Registration Could Lead to Remote Code Execution CWE-306 9.8 Critical 2026-07-17
CVE-2026-10129 SSRF via HTTP Redirect Following in Langflow API Request Component CWE-918 8.5 High 2026-06-30
CVE-2026-10134 Unauthenticated Server-Side RCE via PythonCodeStructuredTool in Public Flows CWE-94 10.0 Critical 2026-06-30
CVE-2026-10140 Cross-Tenant API Key Reuse and Billing Fraud in Langflow Voice Mode Subsystem CWE-639 9.6 Critical 2026-06-30
CVE-2026-10546 DNS Rebinding TOCTOU Bypass of SSRF Protection in Langflow OSS URL Component CWE-918 7.1 High 2026-06-30
CVE-2026-10560 Unauthenticated Access to Private Flow Build Events and Cancellation in Langflow OSS CWE-287 8.2 High 2026-06-30
CVE-2026-10564 SSRF Vulnerability in Langflow OSS Legacy Components Bypasses Protection CWE-918 8.2 High 2026-06-30
CVE-2026-7663 Unauthenticated Cross-User MCP Resource Access and Tool Execution via Streamable Transport Authorization Bypass CWE-285 9.1 Critical 2026-06-30
CVE-2026-7803 Flow Validation Bypass via Empty Component Type Field CWE-20 9.8 Critical 2026-06-30
CVE-2026-7871 Insecure Deserialization in Redis Cache Backend CWE-502 9.8 Critical 2026-06-30
CVE-2026-7873 Code Injection Vulnerability in Code Validation Endpoint CWE-94 9.9 Critical 2026-06-30
CVE-2026-7874 Weak Cryptographic Key Derivation Exposed All Stored Credentials CWE-338 9.1 Critical 2026-06-30
CVE-2026-7664 Unauthenticated Flow Execution via Webhook Endpoint in Langflow OSS CWE-287 9.8 Critical 2026-06-22
CVE-2026-10561 Unauthenticated Remote Code Execution in Langflow OSS PythonREPLComponent via Builtins Injection CWE-94 10.0 Critical 2026-06-22
CVE-2026-7787 Unauthenticated Session History Access via Public Flow Execution CWE-639 7.5 High 2026-06-11
CVE-2026-7528 Unauthenticated File Upload Vulnerability Allows Disk Space Exhaustion and Path Disclosure in Langflow OSS CWE-400 7.1 High 2026-05-27
CVE-2026-7524 Path Traversal Vulnerability in File Processing Components Allows Unauthorized File System Access and Potential Remote Code Execution CWE-22 9.8 Critical 2026-05-27
CVE-2026-6542 Monitor API allows cross-user read of transaction logs and deletion of build data via flow_id CWE-639 6.5 Medium 2026-04-30

All 118 known CVE vulnerabilities affecting Langflow OSS with full Chinese analysis, references, and POCs where available.