Dependency scanning
Check whether langflow is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-48519
Langflow: Unauthenticated RCE in Shareable Playgrounds
CVE-2026-48520
Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read
CVE-2026-42867
Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint
CVE-2026-33760
Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints
CVE-2026-34046
Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check
CVE-2026-34046
Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check
CVE-2026-6599
Langflow vulnerable to injection
CVE-2026-6598
Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint
CVE-2026-21445
Langflow Missing Authentication on Critical API Endpoints
CVE-2026-21445
Langflow Missing Authentication on Critical API Endpoints
CVE-2026-6597
Langflow has an Information Leak through Incomplete API Key Redaction
CVE-2026-6599
Langflow vulnerable to injection
CVE-2026-42867
Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint
CVE-2026-6598
Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint
CVE-2026-6597
Langflow has an Information Leak through Incomplete API Key Redaction
CVE-2026-42048
Langflow Knowledge Bases API is Vulnerable to Path Traversal
CVE-2026-33017
Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint
CVE-2025-57760
CVE-2025-57760
CVE-2025-57760
Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)
CVE-2026-55255
Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
CVE-2024-48061
Langflow vulnerable to remote code execution
CVE-2024-9277
Inefficient Regular Expression Complexity in langflow
CVE-2026-0770
Langflow affected by Remote Code Execution via validate_code() exec()
CVE-2025-68477
Langflow vulnerable to Server-Side Request Forgery
CVE-2024-48061
Langflow vulnerable to remote code execution
CVE-2024-9277
Inefficient Regular Expression Complexity in langflow
CVE-2025-68477
Langflow vulnerable to Server-Side Request Forgery
CVE-2026-0770
Langflow affected by Remote Code Execution via validate_code() exec()
CVE-2026-55447
Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
CVE-2026-27966
Langflow has Remote Code Execution in CSV Agent
CVE-2026-27966
Langflow has Remote Code Execution in CSV Agent
CVE-2026-42048
Langflow Knowledge Bases API is Vulnerable to Path Traversal
CVE-2025-3248
CVE-2025-3248
CVE-2025-3248
Langflow Unauth RCE
CVE-2026-55447
Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
CVE-2026-33017
Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint
CVE-2026-48519
CVE-2026-48519
CVE-2026-48520
CVE-2026-48520
CVE-2026-33760
CVE-2026-33760
CVE-2026-55446
Langflow: Unauthenticated DoS through multipart form boundary file upload
CVE-2026-55450
Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
CVE-2026-55423
Langflow: Logout button does not clear session
CVE-2026-55423
CVE-2026-55423
CVE-2026-55255
CVE-2026-55255
CVE-2026-55450
CVE-2026-55450
CVE-2026-55446
CVE-2026-55446
CVE-2024-37014
CVE-2024-37014
CVE-2025-34291
CVE-2025-34291
CVE-2024-42835
CVE-2024-42835
CVE-2026-33484
langflow has Unauthenticated IDOR on Image Downloads
CVE-2026-33873
Langflow has Authenticated Code Execution in Agentic Assistant Validation
CVE-2026-33053
Langflow is Missing Ownership Verification in API Key Deletion (IDOR)
CVE-2026-33309
Langflow has an Arbitrary File Write (RCE) via v2 API
CVE-2026-33497
langflow: /profile_pictures/{folder_name}/{file_name} endpoint file reading
CVE-2025-68478
External Control of File Name or Path in Langflow
CVE-2024-42835
langflow has vulnerability in PythonCodeTool component
CVE-2025-34291
Langflow CORS misconfiguration enables Account Takeover and RCE
CVE-2026-33873
CVE-2026-33873
CVE-2026-33497
CVE-2026-33497
CVE-2026-33484
CVE-2026-33484
CVE-2026-33309
CVE-2026-33309
CVE-2026-33053
CVE-2026-33053
CVE-2025-68478
CVE-2025-68478
GHSA-c995-4fw3-j39m
Duplicate Advisory: Langflow Vulnerable to Code Injection via the `/api/v1/validate/code` endpoint
CVE-2024-37014
Langflow remote code execution vulnerability
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes