VulnSea

langflow has 57 CVEs on record between 2024 and 2026. Disclosure cadence is accelerating: 35 in the last 90 days against 15 in the 90 before. The busiest recent month was September 2026 with 35. The median CVSS is 8.1 (high), with 9 rated critical. 7% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 98 days (4 cases). The dominant weakness classes are CWE-22 (11) and CWE-918 (7).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
7% vs 1% corpus
Median CVSS
8.1
Publish → KEV
98 d median(4)
Last 90 days
35 prev 15

Products

  • langflow 57
57
Total CVEs
9
Critical
4
CISA KEV
4
Exploited

langflow vulnerabilities

CVEs affecting langflow, newest first. Open any entry for full detail, references, and exploit status.

57 CVEsRSS

CVE-2026-85025Critical· 9.8
1w ago

IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow …

IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow …

Midnightlangflow · langflowEPSS 0.43%via NVD
CVE-2026-81941High· 8.8
1w ago

IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP To…

IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP To…

Twilightlangflow · langflowEPSS 0.76%via NVD
CVE-2026-81940High· 8.8
1w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names.

Twilightlangflow · langflowEPSS 0.55%via NVD
CVE-2026-81268High· 8.1
1w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation.

Twilightlangflow · langflowEPSS 0.31%via NVD
CVE-2026-81211High· 8.8
1w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows.

Twilightlangflow · langflowEPSS 0.34%via NVD
CVE-2026-81204Critical· 9.8
1w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction.

Midnightlangflow · langflowEPSS 0.60%via NVD
CVE-2026-79742High· 8.8
1w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist.

Twilightlangflow · langflowEPSS 0.55%via NVD
CVE-2026-78575High· 8.8
1w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the MCP stdio server configuration.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the MCP stdio server configuration.

Twilightlangflow · langflowEPSS 0.52%via NVD
CVE-2026-78571High· 8.8
1w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an unguarded eval() call on attacker-controlled input.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an unguarded eval() call on attacker-controlled input.

Twilightlangflow · langflowEPSS 0.55%via NVD
CVE-2026-76059High· 8.8
1w ago

IBM Langflow OSS 1.0.0 through 1.11.5 An attacker who could submit custom component source code could bypass the static security scanner by crafting an annotated class-body assignment that resolved to a dangerous callable through alias t…

IBM Langflow OSS 1.0.0 through 1.11.5 An attacker who could submit custom component source code could bypass the static security scanner by crafting an annotated class-body assignment that resolved to a dangerous callable through alias t…

Twilightlangflow · langflowEPSS 0.47%via NVD
CVE-2026-84889High· 8.8
1w ago

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.

Twilightlangflow · langflowEPSS 0.54%via NVD
CVE-2026-79724Critical· 9.8
1w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.

Midnightlangflow · langflowEPSS 0.47%via NVD
CVE-2026-78569High· 8.8
1w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete denylist in the security scanner.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete denylist in the security scanner.

Twilightlangflow · langflowEPSS 0.46%via NVD
CVE-2026-79725Medium· 6.5
1w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to read arbitrary files due to improper access control.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to read arbitrary files due to improper access control.

Sunlitlangflow · langflowEPSS 0.30%via NVD
CVE-2026-79723Medium· 5.0
1w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-controlled API endpoints.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-controlled API endpoints.

Sunlitlangflow · langflowEPSS 0.26%via NVD
CVE-2026-81213High· 8.6
1w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of user-supplied URLs.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of user-supplied URLs.

Twilightlangflow · langflowEPSS 0.36%via NVD
CVE-2026-81265High· 7.5
1w ago

IBM Langflow OSS 1.0.0 through 1.11.5.

IBM Langflow OSS 1.0.0 through 1.11.5.

Twilightlangflow · langflowEPSS 0.23%via NVD
CVE-2026-9225Medium· 6.5
1w ago

IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an authenticated attacker to access sensitive files belonging to other users due to improper access control in the File/Read File component

IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an authenticated attacker to access sensitive files belonging to other users due to improper access control in the File/Read File component. When executing flows through the /api…

Sunlitlangflow · langflowEPSS 0.22%via NVD
CVE-2026-17631Medium· 5.0
2w ago

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability.

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability.

Sunlitlangflow · langflowEPSS 0.23%via NVD
CVE-2026-17627Medium· 4.9
2w ago

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information and inject messages into workflow history due to improper authorization.

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information and inject messages into workflow history due to improper authorization.

Sunlitlangflow · langflowEPSS 0.20%via NVD
CVE-2026-17622Medium· 6.5
2w ago

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.

Sunlitlangflow · langflowEPSS 0.49%via NVD
CVE-2026-17621Medium· 5.4
2w ago

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse directories on the system

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary files on the sys…

Sunlitlangflow · langflowEPSS 0.29%via NVD
CVE-2026-19306High· 7.7
2w ago

IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JWT signing keys, the application database, /proc/self/environ, and…

IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JWT signing keys, the application database, /proc/self/environ, and…

Twilightlangflow · langflowEPSS 0.40%via NVD
CVE-2026-19305High· 8.6
2w ago

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery.

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery.

Twilightlangflow · langflowEPSS 0.29%via NVD
CVE-2026-14470Medium· 6.5
2w ago

IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to traverse directories on the system

IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on th…

Sunlitlangflow · langflowEPSS 0.34%via NVD
CVE-2026-9186Medium· 6.5
2w ago

IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 header, enabling arbitrary writes to IDE config files (~/.cursor/m…

IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 header, enabling arbitrary writes to IDE config files (~/.cursor/m…

Sunlitlangflow · langflowEPSS 0.27%via NVD
CVE-2026-9138Medium· 6.5
2w ago

IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write arbitrary files to the server due to improper input validation in the SaveToFileComponent

IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write arbitrary files to the server due to improper input validation in the SaveToFileComponent. The application constructs local file paths using at…

Sunlitlangflow · langflowEPSS 0.30%via NVD
CVE-2026-8447Medium· 6.1
2w ago

IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored cross-site scripting vulnerability in the Playground chat interface.

IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored cross-site scripting vulnerability in the Playground chat interface.

Sunlitlangflow · langflowEPSS 0.21%via NVD
CVE-2026-19304High· 7.7
2w ago

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information from internal services due to a URL parser discrepancy.

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information from internal services due to a URL parser discrepancy.

Twilightlangflow · langflowEPSS 0.31%via NVD
CVE-2026-19303High· 8.1
2w ago

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrary local files or directories due to improper limitation of a pathname to a restricted directory.

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrary local files or directories due to improper limitation of a pathname to a restricted directory.

Twilightlangflow · langflowEPSS 0.39%via NVD
langflow vulnerabilities (CVEs) · VulnSea