Langflow Vulnerabilities

pip LLM Frameworks

AI Threat Alert tracks 108 known vulnerabilities in Langflow, 42 rated critical — an AI/ML llm frameworks in the pip ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
77
Risk Score
108
Total CVEs
42
Critical
pip
Ecosystem
Aug 13, 2026
Last CVE
24%
Patch Rate
70d
Avg Time to Patch
153,284 stars 9,863 forks 970 issues Last push Aug 16, 2026
View on GitHub

Known Vulnerabilities (108 total, page 1 of 5)

Severity CVE ID Summary CVSS Published
CRITICAL CVE-2026-19297 Langflow: sin límite de intentos permite account takeover 9.1 Aug 13, 2026 CRITICAL CVE-2026-9205 Langflow: weak Fernet key derivation exposes secrets 9.8 Aug 5, 2026 HIGH CVE-2026-9201 Langflow: truncated-hash bypass enables RCE 8.8 Aug 5, 2026 HIGH CVE-2026-9196 Langflow: RCE via unapproved LLM-generated code execution 8.8 Aug 5, 2026 HIGH CVE-2026-9130 Langflow: authz bypass leaks cross-user chat history 7.1 Aug 5, 2026 HIGH CVE-2026-8478 Langflow: RCE via arbitrary code injection (CWE-94) 8.8 Aug 5, 2026 CRITICAL CVE-2026-8470 Langflow: weak PRNG lets attackers decrypt stored secrets 9.1 Aug 5, 2026 HIGH CVE-2026-8183 Langflow: path traversal exposes arbitrary files 7.7 Aug 5, 2026 HIGH CVE-2026-8182 Langflow: pre-auth RCE via chained HTTP requests 8.8 Aug 5, 2026 MEDIUM CVE-2026-7658 Langflow: username path traversal enables data destruction 6.5 Aug 5, 2026 HIGH CVE-2026-9081 IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the validate_model_provider_key() function for the Ollama provider. The function accepts a user-supplied OLLAMA_BASE_URL parameter and passes it directly to requests.get() without validation, scheme/host allowlisting, or filtering of private IP ranges (loopback, RFC1918, link-local addresses). 7.1 Aug 5, 2026 MEDIUM CVE-2026-7657 IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplete and ineffective SSRF protection enforcement. 6.5 Aug 5, 2026 HIGH CVE-2026-17625 IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. 7.2 Aug 5, 2026 MEDIUM CVE-2026-10128 IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbitrary server environment variables, exposing sensitive secrets despite security controls intended to disable custom components. 6.5 Aug 5, 2026 CRITICAL CVE-2026-12946 Langflow: unsanitized code input enables RCE 9.9 Jul 30, 2026 HIGH CVE-2026-13444 Langflow: IDOR exposes/poisons cross-tenant RAG vectors 8.1 Jul 30, 2026 MEDIUM CVE-2026-10700 Langflow: IDOR in file API leaks cross-tenant data 6.5 Jul 30, 2026 HIGH CVE-2026-12942 Langflow: path traversal exposes arbitrary server files 7.5 Jul 30, 2026 CRITICAL CVE-2026-13435 Langflow: PythonREPL sandbox escape enables RCE 9.9 Jul 30, 2026 HIGH CVE-2026-12945 Langflow: IDOR exposes/manipulates other users' builds 7.1 Jul 30, 2026 CRITICAL CVE-2026-12940 Langflow: unauth RCE via MCP env var injection 9.8 Jul 30, 2026 HIGH CVE-2026-13442 Langflow: FAISS namespace reuse leaks cross-user vectors 7.1 Jul 28, 2026 CRITICAL CVE-2026-13446 Langflow: hard-coded credentials enable takeover 9.8 Jul 17, 2026 HIGH CVE-2026-13445 Langflow: SaveToFile flaw breaks user storage isolation 8.1 Jul 17, 2026 CRITICAL CVE-2026-8859 Langflow: path traversal writes arbitrary files 9.9 Jul 17, 2026

Showing 1–25 of 108

Frequently asked questions

What is Langflow?

Langflow is an AI/ML llm frameworks tracked by AI Threat Alert for security vulnerabilities in the pip ecosystem.

How many known vulnerabilities does Langflow have?

Langflow has 108 known CVEs, 42 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is Langflow distributed in?

Langflow is distributed via the pip ecosystem and categorized as llm frameworks.

Where does the Langflow vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of Langflow?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor Langflow in your stack

Get instant alerts when new vulnerabilities affect Langflow. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring