CVE-2026-27966
- EPSS 0.41%
- Veröffentlicht 26.02.2026 01:55:18
- Zuletzt bearbeitet 28.02.2026 00:54:27
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent node in Langflow hardcodes `allow_dangerous_code=True`, which automatically exposes LangChain’s Python REPL tool (`python_repl_ast`)....
CVE-2026-0772
- EPSS 0.87%
- Veröffentlicht 23.01.2026 03:29:01
- Zuletzt bearbeitet 18.02.2026 19:05:00
Langflow Disk Cache Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is required to exploit this vulnerab...
CVE-2026-0771
- EPSS 0.12%
- Veröffentlicht 23.01.2026 03:28:56
- Zuletzt bearbeitet 18.02.2026 19:05:10
Langflow PythonFunction Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Attack vectors and exploitability will vary depending on the confi...
CVE-2026-0770
- EPSS 11.42%
- Veröffentlicht 23.01.2026 03:28:52
- Zuletzt bearbeitet 18.02.2026 16:43:44
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not requ...
CVE-2026-0769
- EPSS 1.96%
- Veröffentlicht 23.01.2026 03:28:47
- Zuletzt bearbeitet 18.02.2026 16:43:31
Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnera...
CVE-2026-0768
- EPSS 2.59%
- Veröffentlicht 23.01.2026 03:28:43
- Zuletzt bearbeitet 18.02.2026 16:43:11
Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific ...
CVE-2026-21445
- EPSS 0.07%
- Veröffentlicht 02.01.2026 19:11:24
- Zuletzt bearbeitet 16.01.2026 18:32:17
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0.dev45, multiple critical API endpoints in Langflow are missing authentication controls. The issue allows any unauthenticated user to access sensitiv...
CVE-2025-68478
- EPSS 0.06%
- Veröffentlicht 19.12.2025 17:10:14
- Zuletzt bearbeitet 02.01.2026 16:20:53
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, if an arbitrary path is specified in the request body's `fs_path`, the server serializes the Flow object into JSON and creates/overwrites a file at...
CVE-2025-68477
- EPSS 0.03%
- Veröffentlicht 19.12.2025 16:43:00
- Zuletzt bearbeitet 02.01.2026 16:21:28
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, Langflow provides an API Request component that can issue arbitrary HTTP requests within a flow. This component takes a user-supplied URL, performs...
CVE-2025-34291
- EPSS 14.04%
- Veröffentlicht 05.12.2025 22:27:26
- Zuletzt bearbeitet 16.01.2026 21:17:02
Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a refresh token...