GHSA-9pw3-x84f-xcwfHigh· 7.4▾ TwilightDuplicate Advisory: Langflow: Weak Fernet Key via random.seed()
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-jxw3-mjmx-3pqm. This link is maintained to preserve external references.
IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.
langflow <= 1.10.0Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-9205Critical· 9.1Langflow: Weak Fernet Key via random.seed()
CVE-2026-7700High· 8.8Langflow: Prompt injection in Langflow Smart Transform can lead to code execution
GHSA-hhxr-7j22-694rLow· 6.3Duplicate Advisory: Prompt injection in Langflow Smart Transform can lead to code execution
GHSA-9cc5-j3qq-69gvCritical· 9.8Duplicate Advisory: Unauthenticated Flow Execution via Webhook Authentication Bypass
GHSA-qqw9-2vj9-hx7rHighDuplicate Advisory: Title Authenticated Remote Code Execution in validate_code via Malicious Decorators Description
CVE-2026-51886High· 8.8langflow-ai langflow v1.9.3 is affected by: Code Injection