- EPSS 0.53%
- Veröffentlicht 22.06.2026 13:22:07
- Zuletzt bearbeitet 26.06.2026 20:19:05
IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in compl...
CVE-2026-12822
- EPSS 0.14%
- Veröffentlicht 21.06.2026 23:30:09
- Zuletzt bearbeitet 26.06.2026 13:35:12
A vulnerability was identified in langflow-ai langflow up to 1.9.3. This affects an unknown function of the component Bundle URL Loader. The manipulation leads to code injection. The attack needs to be performed locally. The vendor was contacted earl...
CVE-2026-7787
- EPSS 0.25%
- Veröffentlicht 11.06.2026 14:41:21
- Zuletzt bearbeitet 16.06.2026 14:58:15
IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information by bypassing authentication using insecure direct object references.
CVE-2026-7528
- EPSS 0.22%
- Veröffentlicht 27.05.2026 13:16:21
- Zuletzt bearbeitet 02.06.2026 15:20:45
IBM Langflow OSS 1.0.0 through 1.9.0 could allow a denial of service due to uncontrolled resource consumption.
CVE-2026-7524
- EPSS 0.62%
- Veröffentlicht 27.05.2026 13:14:23
- Zuletzt bearbeitet 02.06.2026 15:24:15
IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links during archive extraction.
CVE-2026-42048
- EPSS 4.42%
- Veröffentlicht 12.05.2026 17:35:27
- Zuletzt bearbeitet 14.05.2026 12:52:16
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowledge Bases API (DELETE /api/v1/knowledge_bases). This occurs because user-supplied knowledge base name...
CVE-2026-6542
- EPSS 0.2%
- Veröffentlicht 30.04.2026 21:16:10
- Zuletzt bearbeitet 04.05.2026 18:21:23
IBM Langflow OSS 1.0.0 through 1.8.4 could allow any user to supply a flow_id to read transaction logs and vertex build data belonging to other users, and to delete persisted vertex build data for another user's flow.
CVE-2026-3357
- EPSS 0.47%
- Veröffentlicht 08.04.2026 00:19:11
- Zuletzt bearbeitet 14.04.2026 21:28:34
IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, caused by an insecure default setting which permits the deserialization of untrusted data in the FAISS component.
CVE-2026-34046
- EPSS 0.41%
- Veröffentlicht 27.03.2026 20:06:35
- Zuletzt bearbeitet 11.05.2026 14:23:34
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.5.1, the `_read_flow` helper in `src/backend/base/langflow/api/v1/flows.py` branched on the `AUTO_LOGIN` setting to decide whether to filter by `user_id...
CVE-2026-33873
- EPSS 1.43%
- Veröffentlicht 27.03.2026 20:04:23
- Zuletzt bearbeitet 03.04.2026 17:03:54
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.9.0, the Agentic Assistant feature in Langflow executes LLM-generated Python code during its validation phase. Although this phase appears intended to v...