8.8

CVE-2025-57760

Langflow is a tool for building and deploying AI-powered agents and workflows. A privilege escalation vulnerability exists in Langflow containers where an authenticated user with RCE access can invoke the internal CLI command langflow superuser to create a new administrative user. This results in full superuser access, even if the user initially registered through the UI as a regular (non-admin) account. A patched version has not been made public at this time.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LangflowLangflow Version < 1.5.0
LangflowLangflow Version1.5.0 Updatedev0
LangflowLangflow Version1.5.0 Updatedev1
LangflowLangflow Version1.5.0 Updatedev10
LangflowLangflow Version1.5.0 Updatedev11
LangflowLangflow Version1.5.0 Updatedev12
LangflowLangflow Version1.5.0 Updatedev13
LangflowLangflow Version1.5.0 Updatedev14
LangflowLangflow Version1.5.0 Updatedev15
LangflowLangflow Version1.5.0 Updatedev16
LangflowLangflow Version1.5.0 Updatedev17
LangflowLangflow Version1.5.0 Updatedev18
LangflowLangflow Version1.5.0 Updatedev19
LangflowLangflow Version1.5.0 Updatedev2
LangflowLangflow Version1.5.0 Updatedev20
LangflowLangflow Version1.5.0 Updatedev21
LangflowLangflow Version1.5.0 Updatedev22
LangflowLangflow Version1.5.0 Updatedev23
LangflowLangflow Version1.5.0 Updatedev24
LangflowLangflow Version1.5.0 Updatedev25
LangflowLangflow Version1.5.0 Updatedev26
LangflowLangflow Version1.5.0 Updatedev27
LangflowLangflow Version1.5.0 Updatedev28
LangflowLangflow Version1.5.0 Updatedev29
LangflowLangflow Version1.5.0 Updatedev3
LangflowLangflow Version1.5.0 Updatedev30
LangflowLangflow Version1.5.0 Updatedev31
LangflowLangflow Version1.5.0 Updatedev4
LangflowLangflow Version1.5.0 Updatedev5
LangflowLangflow Version1.5.0 Updatedev6
LangflowLangflow Version1.5.0 Updatedev7
LangflowLangflow Version1.5.0 Updatedev8
LangflowLangflow Version1.5.0 Updatedev9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.01% 0.02
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.