34 Total advisories
34 Vulnerabilities
0 Malware
Vulnerabilities
CRITICAL 9.8
CVE-2024-37014
CVE-2024-37014
HIGH 8.8
CVE-2025-34291
CVE-2025-34291
CRITICAL 9.8
CVE-2024-42835
CVE-2024-42835
CRITICAL 9.8
CVE-2026-33017
Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint
HIGH 7.5
CVE-2026-33484
langflow has Unauthenticated IDOR on Image Downloads
UNKNOWN
CVE-2026-33873
Langflow has Authenticated Code Execution in Agentic Assistant Validation
UNKNOWN
CVE-2026-33053
Langflow is Missing Ownership Verification in API Key Deletion (IDOR)
CRITICAL 9.9
CVE-2026-33309
Langflow has an Arbitrary File Write (RCE) via v2 API
UNKNOWN
CVE-2026-33497
langflow: /profile_pictures/{folder_name}/{file_name} endpoint file reading
HIGH 7.1
CVE-2025-68478
External Control of File Name or Path in Langflow
CRITICAL 9.8
CVE-2024-42835
langflow has vulnerability in PythonCodeTool component
HIGH 8.8
CVE-2025-34291
Langflow CORS misconfiguration enables Account Takeover and RCE
CRITICAL 9.9
CVE-2026-33873
CVE-2026-33873
HIGH 7.5
CVE-2026-33497
CVE-2026-33497
HIGH 7.5
CVE-2026-33484
CVE-2026-33484
CRITICAL 9.9
CVE-2026-33309
CVE-2026-33309
HIGH 8.8
CVE-2026-33053
CVE-2026-33053
HIGH 7.1
CVE-2025-68478
CVE-2025-68478
CRITICAL 9.6
CVE-2026-42048
Langflow Knowledge Bases API is Vulnerable to Path Traversal
MEDIUM 6.3
CVE-2026-6599
Langflow vulnerable to injection
MEDIUM 4.3
CVE-2026-6598
Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint
LOW 2.7
CVE-2026-6597
Langflow has an Information Leak through Incomplete API Key Redaction
UNKNOWN
CVE-2025-3248
Langflow Unauth RCE
UNKNOWN
CVE-2026-34046
Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check
CRITICAL 9.8
CVE-2026-27966
Langflow has Remote Code Execution in CSV Agent
UNKNOWN
CVE-2026-0770
Langflow affected by Remote Code Execution via validate_code() exec()
UNKNOWN
CVE-2026-21445
Langflow Missing Authentication on Critical API Endpoints
HIGH 7.7
CVE-2025-68477
Langflow vulnerable to Server-Side Request Forgery
HIGH 8.8
CVE-2025-57760
Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)
CRITICAL 9.8
CVE-2025-3248
CVE-2025-3248
CRITICAL 9.8
GHSA-c995-4fw3-j39m
Duplicate Advisory: Langflow Vulnerable to Code Injection via the `/api/v1/validate/code` endpoint
HIGH 8.8
CVE-2024-37014
Langflow remote code execution vulnerability
CRITICAL 9.8
CVE-2024-48061
Langflow vulnerable to remote code execution
LOW 3.5
CVE-2024-9277
Inefficient Regular Expression Complexity in langflow
Ready to move
Start Securing
Free, no credit card | First findings in minutes