Vulnerabilities
CVE-2026-33017
Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint
CVE-2026-55447
Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
CVE-2026-42048
Langflow Knowledge Bases API is Vulnerable to Path Traversal
CVE-2026-27966
Langflow has Remote Code Execution in CSV Agent
CVE-2026-27966
Langflow has Remote Code Execution in CSV Agent
CVE-2026-42048
Langflow Knowledge Bases API is Vulnerable to Path Traversal
CVE-2025-3248
CVE-2025-3248
CVE-2025-3248
Langflow Unauth RCE
CVE-2026-55447
Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
CVE-2026-33017
Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint
CVE-2026-48520
Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read
CVE-2026-48519
Langflow: Unauthenticated RCE in Shareable Playgrounds
CVE-2026-33760
Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints
CVE-2026-48519
CVE-2026-48519
CVE-2026-48520
CVE-2026-48520
CVE-2026-33760
CVE-2026-33760
CVE-2026-55446
Langflow: Unauthenticated DoS through multipart form boundary file upload
CVE-2026-55255
Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
CVE-2026-55450
Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
CVE-2026-55423
Langflow: Logout button does not clear session
CVE-2026-55423
CVE-2026-55423
CVE-2026-55255
CVE-2026-55255
CVE-2026-55450
CVE-2026-55450
CVE-2026-55446
CVE-2026-55446
CVE-2026-42867
Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint
CVE-2024-37014
CVE-2024-37014
CVE-2025-34291
CVE-2025-34291
CVE-2024-42835
CVE-2024-42835
CVE-2026-33484
langflow has Unauthenticated IDOR on Image Downloads
CVE-2026-33873
Langflow has Authenticated Code Execution in Agentic Assistant Validation
CVE-2026-33053
Langflow is Missing Ownership Verification in API Key Deletion (IDOR)
CVE-2026-33309
Langflow has an Arbitrary File Write (RCE) via v2 API
CVE-2026-33497
langflow: /profile_pictures/{folder_name}/{file_name} endpoint file reading
CVE-2025-68478
External Control of File Name or Path in Langflow
CVE-2024-42835
langflow has vulnerability in PythonCodeTool component
CVE-2025-34291
Langflow CORS misconfiguration enables Account Takeover and RCE
CVE-2026-33873
CVE-2026-33873
CVE-2026-33497
CVE-2026-33497
CVE-2026-33484
CVE-2026-33484
CVE-2026-33309
CVE-2026-33309
CVE-2026-33053
CVE-2026-33053
CVE-2025-68478
CVE-2025-68478
CVE-2026-6599
Langflow vulnerable to injection
CVE-2026-6598
Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint
CVE-2026-6597
Langflow has an Information Leak through Incomplete API Key Redaction
CVE-2026-34046
Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check
CVE-2026-0770
Langflow affected by Remote Code Execution via validate_code() exec()
CVE-2026-21445
Langflow Missing Authentication on Critical API Endpoints
CVE-2025-68477
Langflow vulnerable to Server-Side Request Forgery
CVE-2025-57760
Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)
GHSA-c995-4fw3-j39m
Duplicate Advisory: Langflow Vulnerable to Code Injection via the `/api/v1/validate/code` endpoint
CVE-2024-37014
Langflow remote code execution vulnerability
CVE-2024-48061
Langflow vulnerable to remote code execution
CVE-2024-9277
Inefficient Regular Expression Complexity in langflow
Ready to move
Start Securing
Free, no credit card | First findings in minutes