CVEs we hold for Langflow-ai
Records whose assigning authority named Langflow-ai as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-7700langflow-ai langflow LambdaFilterComponent lambda_filter.p eval code injectionlangflow-ai langflow
CVE-2026-7687langflow-ai langflow Full Builtins code_parser.py CodeParser.parse_callable_details command injectionlangflow-ai langflow
CVE-2026-6600langflow-ai langflow Frontend React Component Rendering edit-message.tsx cross site scriptinglangflow-ai langflow
CVE-2026-6599langflow-ai langflow Model Context Protocol Configuration API mcp_projects.py install_mcp_config injectionlangflow-ai langflow
CVE-2026-6598langflow-ai langflow Project Creation Endpoint projects.py encrypt_auth_settings cleartext storage in filelangflow-ai langflow
CVE-2026-6597langflow-ai langflow Flow Using API core.py has_api_terms credentials storagelangflow-ai langflow
CVE-2026-6596langflow-ai langflow API Endpoint endpoints.py create_upload_file unrestricted uploadlangflow-ai langflow
CVE-2026-55450Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leaklangflow-ai langflow
CVE-2026-55447Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploitlangflow-ai langflow
CVE-2026-55446Langflow: Unauthenticated DoS through multipart form boundary file uploadlangflow-ai langflow
CVE-2026-55255Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's…langflow-ai langflow
CVE-2026-5027Langflow - Path Traversal Arbitrary File Write via upload_user_filelangflow-ai langflow
CVE-2026-48520Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file readlangflow-ai langflow
CVE-2026-42867Langflow: Path Traversal in Knowledge Bases API via Creation Endpointlangflow-ai langflow
CVE-2026-34046Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Checklangflow-ai langflow-base
CVE-2026-33873Langflow has Authenticated Code Execution in Agentic Assistant Validationlangflow-ai langflow
CVE-2026-33760Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpointslangflow-ai langflow
CVE-2026-33497Langflow: /profile_pictures/{folder_name}/{file_name} endpoint file readinglangflow-ai langflow
CVE-2026-33053Langflow has Missing Ownership Verification in API Key Deletion (IDOR)langflow-ai langflow
CVE-2026-33017Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpointlangflow-ai langflow
CVE-2025-57760Langflow Vulnerable to Privilege Escalation via CLI Superuser Creationlangflow-ai langflow
36 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.