65 Total advisories
65 Vulnerabilities
0 Malware

Dependency scanning

Check whether langflow is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

CRITICAL 9.6
PyPI

CVE-2026-48519

Langflow: Unauthenticated RCE in Shareable Playgrounds

MEDIUM 6.1
PyPI

CVE-2026-48520

Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read

MEDIUM 6.5
PyPI

CVE-2026-42867

Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint

HIGH 8.8
PyPI

CVE-2026-33760

Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints

UNKNOWN
PyPI

CVE-2026-34046

Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check

UNKNOWN
PyPI

CVE-2026-34046

Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check

MEDIUM 6.3
PyPI

CVE-2026-6599

Langflow vulnerable to injection

MEDIUM 4.3
PyPI

CVE-2026-6598

Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint

UNKNOWN
PyPI

CVE-2026-21445

Langflow Missing Authentication on Critical API Endpoints

UNKNOWN
PyPI

CVE-2026-21445

Langflow Missing Authentication on Critical API Endpoints

LOW 2.7
PyPI

CVE-2026-6597

Langflow has an Information Leak through Incomplete API Key Redaction

MEDIUM 6.3
PyPI

CVE-2026-6599

Langflow vulnerable to injection

MEDIUM 6.5
PyPI

CVE-2026-42867

Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint

MEDIUM 4.3
PyPI

CVE-2026-6598

Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint

LOW 2.7
PyPI

CVE-2026-6597

Langflow has an Information Leak through Incomplete API Key Redaction

CRITICAL 9.6
PyPI

CVE-2026-42048

Langflow Knowledge Bases API is Vulnerable to Path Traversal

CRITICAL 9.8
PyPI KEV

CVE-2026-33017

Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint

HIGH 8.8
PyPI

CVE-2025-57760

CVE-2025-57760

HIGH 8.8
PyPI

CVE-2025-57760

Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)

HIGH 8.4
PyPI KEV

CVE-2026-55255

Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow

CRITICAL 9.8
PyPI

CVE-2024-48061

Langflow vulnerable to remote code execution

LOW 3.5
PyPI

CVE-2024-9277

Inefficient Regular Expression Complexity in langflow

UNKNOWN
PyPI KEV

CVE-2026-0770

Langflow affected by Remote Code Execution via validate_code() exec()

HIGH 7.7
PyPI

CVE-2025-68477

Langflow vulnerable to Server-Side Request Forgery

CRITICAL 9.8
PyPI

CVE-2024-48061

Langflow vulnerable to remote code execution

LOW 3.5
PyPI

CVE-2024-9277

Inefficient Regular Expression Complexity in langflow

HIGH 7.7
PyPI

CVE-2025-68477

Langflow vulnerable to Server-Side Request Forgery

UNKNOWN
PyPI KEV

CVE-2026-0770

Langflow affected by Remote Code Execution via validate_code() exec()

CRITICAL 9.6
PyPI

CVE-2026-55447

Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit

CRITICAL 9.8
PyPI

CVE-2026-27966

Langflow has Remote Code Execution in CSV Agent

CRITICAL 9.8
PyPI

CVE-2026-27966

Langflow has Remote Code Execution in CSV Agent

CRITICAL 9.6
PyPI

CVE-2026-42048

Langflow Knowledge Bases API is Vulnerable to Path Traversal

CRITICAL 9.8
PyPI KEV

CVE-2025-3248

CVE-2025-3248

UNKNOWN
PyPI KEV

CVE-2025-3248

Langflow Unauth RCE

CRITICAL 9.6
PyPI

CVE-2026-55447

Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit

CRITICAL 9.8
PyPI KEV

CVE-2026-33017

Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint

CRITICAL 9.6
PyPI

CVE-2026-48519

CVE-2026-48519

MEDIUM 6.1
PyPI

CVE-2026-48520

CVE-2026-48520

HIGH 8.8
PyPI

CVE-2026-33760

CVE-2026-33760

HIGH 7.5
PyPI

CVE-2026-55446

Langflow: Unauthenticated DoS through multipart form boundary file upload

CRITICAL 9.3
PyPI

CVE-2026-55450

Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak

MEDIUM 6.1
PyPI

CVE-2026-55423

Langflow: Logout button does not clear session

MEDIUM 6.1
PyPI

CVE-2026-55423

CVE-2026-55423

CRITICAL 9.9
PyPI

CVE-2026-55255

CVE-2026-55255

CRITICAL 9.3
PyPI

CVE-2026-55450

CVE-2026-55450

HIGH 7.5
PyPI

CVE-2026-55446

CVE-2026-55446

CRITICAL 9.8
PyPI

CVE-2024-37014

CVE-2024-37014

HIGH 8.8
PyPI KEV

CVE-2025-34291

CVE-2025-34291

CRITICAL 9.8
PyPI

CVE-2024-42835

CVE-2024-42835

HIGH 7.5
PyPI

CVE-2026-33484

langflow has Unauthenticated IDOR on Image Downloads

UNKNOWN
PyPI

CVE-2026-33873

Langflow has Authenticated Code Execution in Agentic Assistant Validation

UNKNOWN
PyPI

CVE-2026-33053

Langflow is Missing Ownership Verification in API Key Deletion (IDOR)

CRITICAL 9.9
PyPI

CVE-2026-33309

Langflow has an Arbitrary File Write (RCE) via v2 API

UNKNOWN
PyPI

CVE-2026-33497

langflow: /profile_pictures/{folder_name}/{file_name} endpoint file reading

HIGH 7.1
PyPI

CVE-2025-68478

External Control of File Name or Path in Langflow

CRITICAL 9.8
PyPI

CVE-2024-42835

langflow has vulnerability in PythonCodeTool component

HIGH 8.8
PyPI KEV

CVE-2025-34291

Langflow CORS misconfiguration enables Account Takeover and RCE

CRITICAL 9.9
PyPI

CVE-2026-33873

CVE-2026-33873

HIGH 7.5
PyPI

CVE-2026-33497

CVE-2026-33497

HIGH 7.5
PyPI

CVE-2026-33484

CVE-2026-33484

CRITICAL 9.9
PyPI

CVE-2026-33309

CVE-2026-33309

HIGH 8.8
PyPI

CVE-2026-33053

CVE-2026-33053

HIGH 7.1
PyPI

CVE-2025-68478

CVE-2025-68478

CRITICAL 9.8
PyPI

GHSA-c995-4fw3-j39m

Duplicate Advisory: Langflow Vulnerable to Code Injection via the `/api/v1/validate/code` endpoint

HIGH 8.8
PyPI

CVE-2024-37014

Langflow remote code execution vulnerability

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes