Langflow
50 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-10128
MEDIUM 6.5
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to …
2026-08-05
CVE-2026-10547
MEDIUM 5.9
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/buil…
2026-08-05
CVE-2026-17623
HIGH 8.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary command…
2026-08-05
CVE-2026-17624
HIGH 8.5
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0…
2026-08-05
CVE-2026-17625
HIGH 7.2
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0…
2026-08-05
CVE-2026-17626
HIGH 8.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expos…
2026-08-05
CVE-2026-17630
HIGH 7.2
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper …
2026-08-05
CVE-2026-17632
HIGH 8.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code du…
2026-08-05
CVE-2026-17633
HIGH 8.5
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code du…
2026-08-05
CVE-2026-7646
MEDIUM 6.5
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, includi…
2026-08-05
CVE-2026-7657
MEDIUM 6.5
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplet…
2026-08-05
CVE-2026-7658
MEDIUM 6.5
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inj…
2026-08-05
CVE-2026-7869
MEDIUM 5.4
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v…
2026-08-05
CVE-2026-8182
HIGH 8.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on …
2026-08-05
CVE-2026-8183
HIGH 7.7
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0…
2026-08-05
CVE-2026-8446
HIGH 7.5
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Prot…
2026-08-05
CVE-2026-8470
HIGH 7.4
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 us…
2026-08-05
CVE-2026-8478
HIGH 8.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, du…
2026-08-05
CVE-2026-9077
HIGH 8.5
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only …
2026-08-05
CVE-2026-9081
HIGH 7.1
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) …
2026-08-05
CVE-2026-9130
HIGH 7.1
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent tha…
2026-08-05
CVE-2026-9196
HIGH 8.1
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during …
2026-08-05
CVE-2026-9201
HIGH 8.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a…
2026-08-05
CVE-2026-9205
HIGH 7.4
Langflow Oss — IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() functio…
2026-08-05
CVE-2026-10700
MEDIUM 6.5
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handl…
2026-07-30
CVE-2026-12940
CRITICAL 9.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment…
2026-07-30
CVE-2026-12942
HIGH 7.5
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An …
2026-07-30
CVE-2026-12945
HIGH 7.1
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build j…
2026-07-30
CVE-2026-12946
CRITICAL 9.9
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, du…
2026-07-30
CVE-2026-13435
CRITICAL 9.9
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sa…
2026-07-30
CVE-2026-13444
HIGH 8.1
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents …
2026-07-30
CVE-2026-13442
HIGH 7.1
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access …
2026-07-28
CVE-2026-13445
HIGH 8.1
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component …
2026-07-17
CVE-2026-13446
CRITICAL 9.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key…
2026-07-17
CVE-2026-13448
HIGH 8.1
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerabil…
2026-07-17
CVE-2026-14499
HIGH 8.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands…
2026-07-17
CVE-2026-7667
HIGH 8.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to …
2026-07-17
CVE-2026-7754
HIGH 7.7
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to ins…
2026-07-17
CVE-2026-7755
HIGH 8.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation …
2026-07-17
CVE-2026-7872
HIGH 7.5
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the J…
2026-07-17
CVE-2026-8056
HIGH 8.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime v…
2026-07-17
CVE-2026-8476
CRITICAL 9.9
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based…
2026-07-17
CVE-2026-8481
CRITICAL 9.9
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code valid…
2026-07-17
CVE-2026-8505
CRITICAL 9.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows un…
2026-07-17
CVE-2026-8635
CRITICAL 9.9
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by direct…
2026-07-17
CVE-2026-8859
CRITICAL 9.9
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended …
2026-07-17
CVE-2026-9103
CRITICAL 9.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to imprope…
2026-07-17
CVE-2026-9135
CRITICAL 9.9
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc…
2026-07-17
CVE-2026-9198
CRITICAL 9.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPE…● exploited
2026-07-17
CVE-2026-9202
CRITICAL 9.8
Langflow Oss — IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on an…
2026-07-17