Vulnerabilities in langflow-ai

36 results
Vexday analysis

Langflow-AI acumula 36 vulnerabilidades com 13 publicadas nos últimos 90 dias, indicando exposição contínua e recente. Duas vulnerabilidades estão sob ataque ativo em exploração real, enquanto dez atingem nível crítico (CVSS 10), com predominância de injeção de código (CWE-94) — uma categoria de alto impacto em contextos de execução remota. A velocidade de disclosure e a presença de exploits documentados demandam priorização imediata na atualização de dependências.

CVE-2025-3248CRITICALLangflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/codeEPSS 100.0%KEVCVE-2026-33017CRITICALLangflow has Unauthenticated Remote Code Execution via Public Flow Build EndpointEPSS 99.8%KEVCVE-2026-21445HIGHLangflow Missing Authentication on Critical API EndpointsEPSS 34.1%CVE-2026-27966CRITICALLangflow has Remote Code Execution in CSV AgentEPSS 33.7%CVE-2026-5027HIGHLangflow - Path Traversal Arbitrary File Write via upload_user_fileEPSS 31.4%CVE-2026-55255HIGHLangflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's FlowEPSS 29.1%CVE-2026-33497HIGHLangflow: /profile_pictures/{folder_name}/{file_name} endpoint file readingEPSS 19.6%CVE-2026-33309CRITICALLangflow has an Arbitrary File Write (RCE) via v2 APIEPSS 12.4%CVE-2026-55450CRITICALLangflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leakEPSS 11.8%CVE-2025-68477HIGHLangflow vulnerable to Server-Side Request ForgeryEPSS 6.0%CVE-2026-33484HIGHLangflow has Unauthenticated IDOR on Image DownloadsEPSS 5.8%CVE-2026-42048CRITICALLangflow: Path Traversal in Langflow Knowledge Bases APIEPSS 4.4%CVE-2025-68478HIGHLangflow Vulnerable to External Control of File Name or PathEPSS 3.9%CVE-2026-33475CRITICALLangflow GitHub Actions Shell InjectionEPSS 3.0%CVE-2026-7687MEDIUMlangflow-ai langflow Full Builtins code_parser.py CodeParser.parse_callable_details command injectionEPSS 1.7%CVE-2026-33873CRITICALLangflow has Authenticated Code Execution in Agentic Assistant ValidationEPSS 1.4%CVE-2026-48519CRITICALLangflow: Unauthenticated RCE in Shareable PlaygroundsEPSS 0.8%CVE-2026-55447CRITICALLangflow: BaseFileComponent-based nodes arbitrary file read with RCE exploitEPSS 0.5%CVE-2026-34046HIGHLangflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership CheckEPSS 0.5%CVE-2025-57760HIGHLangflow Vulnerable to Privilege Escalation via CLI Superuser CreationEPSS 0.5%