8.8

CVE-2025-57760

Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation

Langflow is a tool for building and deploying AI-powered agents and workflows. A privilege escalation vulnerability exists in Langflow containers where an authenticated user with RCE access can invoke the internal CLI command langflow superuser to create a new administrative user. This results in full superuser access, even if the user initially registered through the UI as a regular (non-admin) account. A patched version has not been made public at this time.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LangflowLangflow Version < 1.5.0
LangflowLangflow Version1.5.0 Updatedev0
LangflowLangflow Version1.5.0 Updatedev1
LangflowLangflow Version1.5.0 Updatedev10
LangflowLangflow Version1.5.0 Updatedev11
LangflowLangflow Version1.5.0 Updatedev12
LangflowLangflow Version1.5.0 Updatedev13
LangflowLangflow Version1.5.0 Updatedev14
LangflowLangflow Version1.5.0 Updatedev15
LangflowLangflow Version1.5.0 Updatedev16
LangflowLangflow Version1.5.0 Updatedev17
LangflowLangflow Version1.5.0 Updatedev18
LangflowLangflow Version1.5.0 Updatedev19
LangflowLangflow Version1.5.0 Updatedev2
LangflowLangflow Version1.5.0 Updatedev20
LangflowLangflow Version1.5.0 Updatedev21
LangflowLangflow Version1.5.0 Updatedev22
LangflowLangflow Version1.5.0 Updatedev23
LangflowLangflow Version1.5.0 Updatedev24
LangflowLangflow Version1.5.0 Updatedev25
LangflowLangflow Version1.5.0 Updatedev26
LangflowLangflow Version1.5.0 Updatedev27
LangflowLangflow Version1.5.0 Updatedev28
LangflowLangflow Version1.5.0 Updatedev29
LangflowLangflow Version1.5.0 Updatedev3
LangflowLangflow Version1.5.0 Updatedev30
LangflowLangflow Version1.5.0 Updatedev31
LangflowLangflow Version1.5.0 Updatedev4
LangflowLangflow Version1.5.0 Updatedev5
LangflowLangflow Version1.5.0 Updatedev6
LangflowLangflow Version1.5.0 Updatedev7
LangflowLangflow Version1.5.0 Updatedev8
LangflowLangflow Version1.5.0 Updatedev9
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.43% 0.344
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

https://github.com/langflow-ai/langflow/security/advisories/GHSA-4gv9-mp8m-592r
Third Party Advisory
https://github.com/langflow-ai/langflow/commit/c188ec113c9ca46154ad01d0eded1754cc6bef97
Patch
http://github.com/langflow-ai/langflow/pull/9152
Patch