Langflow oss
This hub aggregates every CVE we track for Langflow oss, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
43
CVEs tracked
23
Critical
18
High
0
In CISA KEV
Severity distribution
CRITICAL23HIGH18MEDIUM2
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
2
14
26
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Langflow oss.
- CVE-2026-12946Remote Code Execution in CUGA Component CodeAgent9.9
- CVE-2026-13444Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints8.1
- CVE-2026-10700Broken Access Control Vulnerabilities in Langflow 1.0.0 - 1.8.4 File Handling API Allowed Unauthorized Access to User Files6.5
- CVE-2026-13435Python Interpreter Sandbox Bypass Leading to Sensitive Data Exposure9.9
- CVE-2026-12942Langflow is affected by path traversal due to multiple unauthenticated and insufficiently authorized API endpoints7.5
- CVE-2026-12945Langflow is affected by exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints7.1
- CVE-2026-12940Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpoints9.8
- CVE-2026-13442Langflow is affected by NET Misconfiguration: Use of Impersonation due to multiple unauthenticated and insufficiently authorized API endpoints7.1
- CVE-2026-13445Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints8.1
- CVE-2026-13446Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints9.8
- CVE-2026-13448Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints8.1
- CVE-2026-14499Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints8.8
- CVE-2026-7667Path Traversal Vulnerability in API Request Component Content-Disposition Header Processing8.8
- CVE-2026-7754SSRF Protection Configuration Vulnerability7.7
- CVE-2026-7755MCP Server Configuration Validator Bypass via File Upload API8.8
Product normalization is registry-driven with AI assist and human review. How it works