VulnSea

langflow has 57 CVEs on record between 2024 and 2026. Disclosure cadence is accelerating: 35 in the last 90 days against 13 in the 90 before. The busiest recent month was September 2026 with 35. The median CVSS is 8.1 (high), with 9 rated critical. 7% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 98 days (4 cases). The dominant weakness classes are CWE-22 (11) and CWE-918 (7).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
7% vs 1% corpus
Median CVSS
8.1
Publish → KEV
98 d median(4)
Last 90 days
35 prev 13

Products

  • langflow 57
57
Total CVEs
9
Critical
4
CISA KEV
4
Exploited

langflow vulnerabilities

CVEs affecting langflow, newest first. Open any entry for full detail, references, and exploit status.

57 CVEsRSS

CVE-2026-19302Medium· 6.5
3w ago

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.

▾ Sunlitlangflow · langflowEPSS 0.49%via NVD
CVE-2026-19301Medium· 5.0
3w ago

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery.

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery.

▾ Sunlitlangflow · langflowEPSS 0.29%via NVD
CVE-2026-19300High· 7.5
3w ago

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields.

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields.

▾ Twilightlangflow · langflowEPSS 0.38%via NVD
CVE-2026-19299Medium· 6.5
3w ago

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to path traversal.

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to path traversal.

▾ Sunlitlangflow · langflowEPSS 0.49%via NVD
CVE-2026-19298High· 8.8
3w ago

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process.

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process.

▾ Twilightlangflow · langflowEPSS 0.50%via NVD
CVE-2026-55255Critical· 9.9CISA KEVPoC
3mo ago

Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow

Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow

▾ Hadallangflow · langflowEPSS 0.89%via GHSA
CVE-2026-55423Medium· 6.1
3mo ago

Langflow: Logout button does not clear session

Langflow: Logout button does not clear session

▾ Sunlitlangflow · langflowEPSS 0.22%via OSV
CVE-2026-55446High· 7.5
3mo ago

Langflow: Unauthenticated DoS through multipart form boundary file upload

Langflow: Unauthenticated DoS through multipart form boundary file upload

▾ Twilightlangflow · langflowEPSS 0.58%via GHSA
CVE-2026-55447Critical· 9.6
3mo ago

Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit

Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit

▾ Midnightlangflow · langflowEPSS 0.66%via GHSA
CVE-2026-55450Critical· 9.3PoC
3mo ago

Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak

Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak

▾ Abyssallangflow · langflowEPSS 1.2%via GHSA
CVE-2026-33760High· 8.8
3mo ago

Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints

Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints

▾ Twilightlangflow · langflowEPSS 0.50%via GHSA
CVE-2026-42867Medium· 6.5
3mo ago

Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint

Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint

▾ Sunlitlangflow · langflowEPSS 0.47%via GHSA
CVE-2026-48519Critical· 9.6PoC
3mo ago

Langflow: Unauthenticated RCE in Shareable Playgrounds

Langflow: Unauthenticated RCE in Shareable Playgrounds

▾ Abyssallangflow · langflowEPSS 0.78%via GHSA
CVE-2026-48520Medium· 6.1
3mo ago

Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read

Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read

▾ Sunlitlangflow · langflowEPSS 0.44%via GHSA
CVE-2026-6599Medium· 6.3
5mo ago

Langflow vulnerable to injection

Langflow vulnerable to injection

▾ Sunlitlangflow · langflowEPSS 0.39%via OSV
CVE-2026-6598Medium· 4.3
5mo ago

Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint

Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint

▾ Sunlitlangflow · langflowEPSS 0.24%via OSV
CVE-2026-6597Low· 2.7
5mo ago

Langflow has an Information Leak through Incomplete API Key Redaction

Langflow has an Information Leak through Incomplete API Key Redaction

▾ Sunlitlangflow · langflowEPSS 0.38%via OSV
CVE-2026-3357High· 8.8
5mo ago

IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, caused by an insecure default setting which permits the deserialization of untrusted data in the FAISS component.

IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, caused by an insecure default setting which permits the deserialization of untrusted data in the FAISS component.

▾ Twilightlangflow · langflowEPSS 0.65%via NVD
CVE-2026-5027High· 8.8PoC
6mo ago

The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').

The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').

▾ Midnightlangflow · langflowEPSS 4.8%via NVD
CVE-2026-34046High
6mo ago

Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check

Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check

▾ Twilightlangflow · langflowEPSS 0.68%via OSV
CVE-2026-0770HighCISA KEV0dayPoC
8mo ago

Langflow affected by Remote Code Execution via validate_code() exec()

Langflow affected by Remote Code Execution via validate_code() exec()

▾ Abyssallangflow · langflowEPSS 64%via OSV
CVE-2025-68477High· 7.7
9mo ago

Langflow vulnerable to Server-Side Request Forgery

Langflow vulnerable to Server-Side Request Forgery

▾ Twilightlangflow · langflowEPSS 6.3%via OSV
CVE-2025-34291High· 8.8CISA KEVPoC
9mo ago

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a …

▾ Abyssallangflow · langflowEPSS 93%via NVD
CVE-2025-57760High· 8.8
1y ago

Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)

Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)

▾ Twilightlangflow · langflowEPSS 0.52%via OSV
CVE-2025-3248Critical· 9.8CISA KEVPoC
1y ago

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.

▾ Hadallangflow · langflowEPSS 100%via NVD
CVE-2024-48061Critical· 9.8PoC
1y ago

Langflow vulnerable to remote code execution

Langflow vulnerable to remote code execution

▾ Abyssallangflow · langflowEPSS 1.5%via OSV
CVE-2024-9277Low· 3.5
1y ago

Inefficient Regular Expression Complexity in langflow

Inefficient Regular Expression Complexity in langflow

▾ Sunlitlangflow · langflowEPSS 0.96%via OSV
langflow vulnerabilities (CVEs) — page 2 · VulnSea