Langflow

Langflow

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Veröffentlicht 25.08.2025 16:22:17
  • Zuletzt bearbeitet 03.09.2025 13:56:12

Langflow is a tool for building and deploying AI-powered agents and workflows. A privilege escalation vulnerability exists in Langflow containers where an authenticated user with RCE access can invoke the internal CLI command langflow superuser to cr...

Warnung Medienbericht Exploit
  • EPSS 92.08%
  • Veröffentlicht 07.04.2025 14:22:38
  • Zuletzt bearbeitet 06.11.2025 13:57:48

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.

Exploit
  • EPSS 10.17%
  • Veröffentlicht 04.11.2024 23:15:04
  • Zuletzt bearbeitet 28.05.2025 20:56:46

langflow <=1.0.18 is vulnerable to Remote Code Execution (RCE) as any component provided the code functionality and the components run on the local machine rather than in a sandbox.

Exploit
  • EPSS 12.63%
  • Veröffentlicht 31.10.2024 14:15:05
  • Zuletzt bearbeitet 27.05.2025 20:34:39

langflow v1.0.12 was discovered to contain a remote code execution (RCE) vulnerability via the PythonCodeTool component.

Exploit
  • EPSS 0.17%
  • Veröffentlicht 27.09.2024 11:15:14
  • Zuletzt bearbeitet 05.06.2025 20:08:14

A vulnerability classified as problematic was found in Langflow up to 1.0.18. Affected by this vulnerability is an unknown functionality of the file \src\backend\base\langflow\interface\utils.py of the component HTTP POST Request Handler. The manipul...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 30.07.2024 17:15:14
  • Zuletzt bearbeitet 24.06.2025 16:38:15

Langflow versions prior to 1.0.13 suffer from a Privilege Escalation vulnerability, allowing a remote and low privileged attacker to gain super admin privileges by performing a mass assignment request on the '/api/v1/users' endpoint.

Exploit
  • EPSS 6.5%
  • Veröffentlicht 10.06.2024 20:15:15
  • Zuletzt bearbeitet 21.11.2024 09:23:02

Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and provide a Python script.