10 Total advisories
10 Vulnerabilities
0 Malware
Dependency scanning
Check whether langflow-base is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2026-34046
Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check
UNKNOWN
CVE-2026-34046
Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check
HIGH 7.3
CVE-2026-6596
Langflow: DoS Through Lack of File Size Restriction via Deprecated Unauthenticated File Upload API
UNKNOWN
CVE-2026-21445
Langflow Missing Authentication on Critical API Endpoints
UNKNOWN
CVE-2026-21445
Langflow Missing Authentication on Critical API Endpoints
HIGH 7.3
CVE-2026-6596
Langflow: DoS Through Lack of File Size Restriction via Deprecated Unauthenticated File Upload API
HIGH 8.8
CVE-2025-57760
Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)
HIGH 8.8
CVE-2025-57760
Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)
UNKNOWN
CVE-2025-3248
Langflow Unauth RCE
UNKNOWN
CVE-2025-3248
Langflow Unauth RCE
Browse more PyPI advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes