Langflow Vulnerabilities

pip LLM Frameworks

AI Threat Alert tracks 162 known vulnerabilities in Langflow, 47 rated critical — an AI/ML llm frameworks in the pip ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
77
Risk Score
162
Total CVEs
47
Critical
pip
Ecosystem
Sep 10, 2026
Last CVE
17%
Patch Rate
73d
Avg Time to Patch
155,288 stars 10,150 forks 1,188 issues Last push Sep 27, 2026
View on GitHub

Known Vulnerabilities (162 total, page 2 of 7)

Severity CVE ID Summary CVSS Published
HIGH CVE-2026-19303 Langflow: path traversal enables arbitrary file deletion 8.1 Sep 4, 2026 MEDIUM CVE-2026-19302 Langflow: symlink flaw leaks sensitive files 6.5 Sep 4, 2026 MEDIUM CVE-2026-19301 Langflow: SSRF allows internal network reconnaissance 6.5 Sep 4, 2026 HIGH CVE-2026-19300 Langflow: leaky credential fields expose secrets 7.5 Sep 4, 2026 MEDIUM CVE-2026-19299 Langflow: authenticated path traversal leaks files 6.5 Sep 4, 2026 HIGH CVE-2026-19298 Langflow: auth bypass in flow build enables RCE 8.8 Sep 4, 2026 MEDIUM CVE-2026-9186 Langflow: header spoof bypasses MCP config write guard 6.5 Sep 4, 2026 MEDIUM CVE-2026-9138 Langflow: path traversal enables arbitrary file write 6.5 Sep 4, 2026 MEDIUM CVE-2026-8447 Langflow: stored XSS in Playground chat UI 6.1 Sep 4, 2026 CRITICAL CVE-2026-19295 Langflow: auth'd RCE bypasses custom-component block 9.9 Aug 28, 2026 MEDIUM CVE-2026-19294 Langflow: authz flaw lets users run others' AI flows 6.5 Aug 28, 2026 CRITICAL CVE-2026-19286 Langflow: unauthenticated RCE via A2A endpoint 9.8 Aug 28, 2026 HIGH CVE-2026-18904 Langflow: namespace collision leaks data, injects messages 8.2 Aug 28, 2026 HIGH CVE-2026-18899 Langflow: path traversal enables arbitrary file read 7.5 Aug 28, 2026 HIGH CVE-2026-18891 Langflow: broken auth allows unauthorized flow execution 8.2 Aug 28, 2026 HIGH CVE-2026-18729 Langflow: authenticated RCE via unsafe code generation 8.8 Aug 28, 2026 MEDIUM CVE-2026-18545 Langflow: SSRF lets authenticated users probe internal network 4.3 Aug 28, 2026 HIGH CVE-2026-19875 Langflow: missing auth allows admin takeover 7.5 Aug 19, 2026 CRITICAL CVE-2026-19297 Langflow: sin límite de intentos permite account takeover 9.1 Aug 13, 2026 CRITICAL CVE-2026-9205 Langflow: weak Fernet key derivation exposes secrets 9.8 Aug 5, 2026 HIGH CVE-2026-9201 Langflow: truncated-hash bypass enables RCE 8.8 Aug 5, 2026 HIGH CVE-2026-9196 Langflow: RCE via unapproved LLM-generated code execution 8.8 Aug 5, 2026 HIGH CVE-2026-9130 Langflow: authz bypass leaks cross-user chat history 7.1 Aug 5, 2026 HIGH CVE-2026-8478 Langflow: RCE via arbitrary code injection (CWE-94) 8.8 Aug 5, 2026 CRITICAL CVE-2026-8470 Langflow: weak PRNG lets attackers decrypt stored secrets 9.1 Aug 5, 2026

Showing 26–50 of 162

Frequently asked questions

What is Langflow?

Langflow is an AI/ML llm frameworks tracked by AI Threat Alert for security vulnerabilities in the pip ecosystem.

How many known vulnerabilities does Langflow have?

Langflow has 162 known CVEs, 47 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is Langflow distributed in?

Langflow is distributed via the pip ecosystem and categorized as llm frameworks.

Where does the Langflow vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of Langflow?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor Langflow in your stack

Get instant alerts when new vulnerabilities affect Langflow. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring