lfx vulnerabilities
CVEs whose affected-version data names the lfx package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
GHSA-j8f7-x8jm-wmm4MediumLangflow: SSRF in URL-taking components (protection disabled by default / warn-only, not applied to RSS, SearXNG, Web Search, Home Assistant, Glean, Docling)
Langflow: SSRF in URL-taking components (protection disabled by default / warn-only, not applied to RSS, SearXNG, Web Search, Home Assistant, Glean, Docling)
▾ Sunlitlangflow · langflowvia GHSA
CVE-2026-105697Critical· 9.9Langflow is a tool for building and deploying AI-powered agents and workflows
Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP stdio transport launched whatever command / args a user put in an MCP server configuration, with no allowlist and (before 1.10…
▾ Midnightlangflow-ai · langflowvia NVD