Langflow

Langflow

46 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.22%
  • Veröffentlicht 23.06.2026 16:31:27
  • Zuletzt bearbeitet 26.06.2026 17:06:40

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.10.0, the "Shareable Playground" (or "Public Flows" in code) contains a potential arbitrary file-read vulnerability, depending on the exact flow configuration u...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 23.06.2026 16:30:16
  • Zuletzt bearbeitet 26.06.2026 17:10:06

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow's /api/v1/monitor router exposes 7 endpoints that perform read, write, and delete operations on user-owned resources — messages, sessions, build a...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 23.06.2026 16:29:11
  • Zuletzt bearbeitet 26.06.2026 17:09:16

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowledge Bases API (POST /api/v1/knowledge_bases). This occurs because user-supplied knowledge base names ...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 23.06.2026 16:28:20
  • Zuletzt bearbeitet 24.06.2026 13:47:59

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to an...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 23.06.2026 16:27:19
  • Zuletzt bearbeitet 24.06.2026 13:50:27

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.7.0, the logout button does not clear the session. The previous user stays logged in unless another user explicitly logs in. This vulnerability is fixed in 1.7....

Exploit
  • EPSS 0.32%
  • Veröffentlicht 23.06.2026 16:26:17
  • Zuletzt bearbeitet 24.06.2026 13:50:33

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.0.19, an attacker can send a /api/v1/files/upload/ request without any authentication token/cookies and abuse a very long multipart form boundary to make the la...

Exploit
  • EPSS 0.55%
  • Veröffentlicht 23.06.2026 16:25:09
  • Zuletzt bearbeitet 26.06.2026 17:07:36

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, the "Shareable Playground" (or "Public Flows" in code) contains a critical RCE vulnerability. Shareable Playground feature works by enabling the execution ...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 23.06.2026 16:21:42
  • Zuletzt bearbeitet 24.06.2026 17:17:29

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling a files that are digested into the RAG, an attacker can direct the node to read any file on the file-system by absolute path. All components...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 23.06.2026 16:17:52
  • Zuletzt bearbeitet 24.06.2026 13:50:45

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can upload any amount of data to the server without any limitations. No need for any prior knowledge, only network access to Langflow...

  • EPSS 0.28%
  • Veröffentlicht 22.06.2026 14:10:25
  • Zuletzt bearbeitet 26.06.2026 21:29:37

IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.