Vulnerabilities in langflow-ai

36 results
Vexday analysis

Langflow-AI acumula 36 vulnerabilidades com 13 publicadas nos últimos 90 dias, indicando exposição contínua e recente. Duas vulnerabilidades estão sob ataque ativo em exploração real, enquanto dez atingem nível crítico (CVSS 10), com predominância de injeção de código (CWE-94) — uma categoria de alto impacto em contextos de execução remota. A velocidade de disclosure e a presença de exploits documentados demandam priorização imediata na atualização de dependências.

CVE-2025-3248CRITICALLangflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/codeEPSS 100.0%KEVCVE-2026-33017CRITICALLangflow has Unauthenticated Remote Code Execution via Public Flow Build EndpointEPSS 96.2%KEVCVE-2026-5027HIGHLangflow - Path Traversal Arbitrary File Write via upload_user_fileEPSS 36.1%CVE-2026-21445HIGHLangflow Missing Authentication on Critical API EndpointsEPSS 33.7%CVE-2026-27966CRITICALLangflow has Remote Code Execution in CSV AgentEPSS 33.7%CVE-2026-33497HIGHLangflow: /profile_pictures/{folder_name}/{file_name} endpoint file readingEPSS 19.6%CVE-2026-33309CRITICALLangflow has an Arbitrary File Write (RCE) via v2 APIEPSS 11.1%CVE-2025-68477HIGHLangflow vulnerable to Server-Side Request ForgeryEPSS 6.3%CVE-2026-33484HIGHLangflow has Unauthenticated IDOR on Image DownloadsEPSS 5.8%CVE-2026-42048CRITICALLangflow: Path Traversal in Langflow Knowledge Bases APIEPSS 4.4%CVE-2025-68478HIGHLangflow Vulnerable to External Control of File Name or PathEPSS 4.1%CVE-2026-33475CRITICALLangflow GitHub Actions Shell InjectionEPSS 3.1%CVE-2026-7687MEDIUMlangflow-ai langflow Full Builtins code_parser.py CodeParser.parse_callable_details command injectionEPSS 2.5%CVE-2026-33873CRITICALLangflow has Authenticated Code Execution in Agentic Assistant ValidationEPSS 1.4%CVE-2026-55450CRITICALLangflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leakEPSS 1.2%CVE-2026-55255HIGHLangflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's FlowEPSS 0.9%CVE-2026-48519CRITICALLangflow: Unauthenticated RCE in Shareable PlaygroundsEPSS 0.8%CVE-2026-55447CRITICALLangflow: BaseFileComponent-based nodes arbitrary file read with RCE exploitEPSS 0.7%CVE-2026-55446HIGHLangflow: Unauthenticated DoS through multipart form boundary file uploadEPSS 0.6%CVE-2026-33760HIGHLangflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 EndpointsEPSS 0.5%