Launch Week Day 1: Announcing Security Design Review
34 Total advisories
34 Vulnerabilities
0 Malware

Vulnerabilities

CRITICAL 9.8
PyPI

CVE-2024-37014

CVE-2024-37014

HIGH 8.8
PyPI KEV

CVE-2025-34291

CVE-2025-34291

CRITICAL 9.8
PyPI

CVE-2024-42835

CVE-2024-42835

CRITICAL 9.8
PyPI KEV

CVE-2026-33017

Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint

HIGH 7.5
PyPI

CVE-2026-33484

langflow has Unauthenticated IDOR on Image Downloads

UNKNOWN
PyPI

CVE-2026-33873

Langflow has Authenticated Code Execution in Agentic Assistant Validation

UNKNOWN
PyPI

CVE-2026-33053

Langflow is Missing Ownership Verification in API Key Deletion (IDOR)

CRITICAL 9.9
PyPI

CVE-2026-33309

Langflow has an Arbitrary File Write (RCE) via v2 API

UNKNOWN
PyPI

CVE-2026-33497

langflow: /profile_pictures/{folder_name}/{file_name} endpoint file reading

HIGH 7.1
PyPI

CVE-2025-68478

External Control of File Name or Path in Langflow

CRITICAL 9.8
PyPI

CVE-2024-42835

langflow has vulnerability in PythonCodeTool component

HIGH 8.8
PyPI KEV

CVE-2025-34291

Langflow CORS misconfiguration enables Account Takeover and RCE

CRITICAL 9.9
PyPI

CVE-2026-33873

CVE-2026-33873

HIGH 7.5
PyPI

CVE-2026-33497

CVE-2026-33497

HIGH 7.5
PyPI

CVE-2026-33484

CVE-2026-33484

CRITICAL 9.9
PyPI

CVE-2026-33309

CVE-2026-33309

HIGH 8.8
PyPI

CVE-2026-33053

CVE-2026-33053

HIGH 7.1
PyPI

CVE-2025-68478

CVE-2025-68478

CRITICAL 9.6
PyPI

CVE-2026-42048

Langflow Knowledge Bases API is Vulnerable to Path Traversal

MEDIUM 6.3
PyPI

CVE-2026-6599

Langflow vulnerable to injection

MEDIUM 4.3
PyPI

CVE-2026-6598

Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint

LOW 2.7
PyPI

CVE-2026-6597

Langflow has an Information Leak through Incomplete API Key Redaction

UNKNOWN
PyPI KEV

CVE-2025-3248

Langflow Unauth RCE

UNKNOWN
PyPI

CVE-2026-34046

Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check

CRITICAL 9.8
PyPI

CVE-2026-27966

Langflow has Remote Code Execution in CSV Agent

UNKNOWN
PyPI

CVE-2026-0770

Langflow affected by Remote Code Execution via validate_code() exec()

UNKNOWN
PyPI

CVE-2026-21445

Langflow Missing Authentication on Critical API Endpoints

HIGH 7.7
PyPI

CVE-2025-68477

Langflow vulnerable to Server-Side Request Forgery

HIGH 8.8
PyPI

CVE-2025-57760

Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)

CRITICAL 9.8
PyPI KEV

CVE-2025-3248

CVE-2025-3248

CRITICAL 9.8
PyPI

GHSA-c995-4fw3-j39m

Duplicate Advisory: Langflow Vulnerable to Code Injection via the `/api/v1/validate/code` endpoint

HIGH 8.8
PyPI

CVE-2024-37014

Langflow remote code execution vulnerability

CRITICAL 9.8
PyPI

CVE-2024-48061

Langflow vulnerable to remote code execution

LOW 3.5
PyPI

CVE-2024-9277

Inefficient Regular Expression Complexity in langflow

Ready to move

Start Securing

Free, no credit card | First findings in minutes