Langflow

Langflow

178 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.53%
  • Veröffentlicht 10.09.2026 21:25:05
  • Zuletzt bearbeitet 14.09.2026 20:11:04

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.

  • EPSS 0.43%
  • Veröffentlicht 10.09.2026 20:58:37
  • Zuletzt bearbeitet 15.09.2026 17:19:17

IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow security rest...

  • EPSS 0.23%
  • Veröffentlicht 10.09.2026 20:44:30
  • Zuletzt bearbeitet 15.09.2026 17:09:46

IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an authenticated attacker to access sensitive files belonging to other users due to improper access control in the File/Read File component. When executing flows through the /api/v1/run/advan...

  • EPSS 0.33%
  • Veröffentlicht 04.09.2026 16:43:36
  • Zuletzt bearbeitet 10.09.2026 16:17:07

IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

  • EPSS 0.18%
  • Veröffentlicht 04.09.2026 16:30:14
  • Zuletzt bearbeitet 09.09.2026 15:05:03

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information and inject messages into workflow history due to improper authorization.

  • EPSS 0.27%
  • Veröffentlicht 04.09.2026 16:29:57
  • Zuletzt bearbeitet 10.09.2026 21:17:22

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary files on the system.

  • EPSS 0.48%
  • Veröffentlicht 04.09.2026 16:29:33
  • Zuletzt bearbeitet 09.09.2026 15:06:06

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.

  • EPSS 0.2%
  • Veröffentlicht 04.09.2026 16:28:37
  • Zuletzt bearbeitet 09.09.2026 15:01:37

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability.

  • EPSS 0.38%
  • Veröffentlicht 04.09.2026 16:17:24
  • Zuletzt bearbeitet 10.09.2026 21:17:25

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrary local files or directories due to improper limitation of a pathname to a restricted directory.

  • EPSS 0.24%
  • Veröffentlicht 04.09.2026 16:17:22
  • Zuletzt bearbeitet 08.09.2026 22:16:54

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery.