Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2629▼ 216 respecto a la semana anterior
Críticas / altas1378▲ 154 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
176 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Sin puntuar | 0.23% | — | LangflowAI | 1/10/2026 | 2/10/2026 | langflow-ai langflow v1.8.4 is affected by: Directory Traversal. The impact is: Arbitrary file write outside the intended workspace or storage boundary.. The component is: src/backend/base/langflow/api/v1/knowledge_bases.py:knowledge_bases-create_knowledge_base-a-live-http-post-to-create-knowledge-base. The attack… | |
| Pendiente de análisis | Sin puntuar | 0.17% | — | LangflowAI | 1/10/2026 | 2/10/2026 | langflow-ai langflow v1.9.3 is affected by: Code Injection. The impact is: execute arbitrary code (remote). The component is: src/backend/base/langflow/api/v1/validate.py:validate-post_validate_code-a-real-authenticated-http-post-to-api-v1. The attack vector is: Attack surface: HTTP or browser-backed service path. A… | |
| Pendiente de análisis | Baja (2.1) | 0.20% | — | LangflowAI | 28/9/2026 | 30/9/2026 | Langflow 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() vulnerability in schema.py that allows authenticated attackers to achieve code execution by placing a Python object with a malicious __repr__ method into component input options lists. The eval() sink is triggered when a component is… | |
| Pendiente de análisis | Crítica (9.6) | 0.43% | — | IBM LangflowAI | 14/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential theft via IMDSv1 SSRF with full IAM role permissions, (2) arbitrary file… | |
| Pendiente de análisis | Media (6.5) | 0.22% | — | IBM LangflowAI | 14/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Pendiente de análisis | Media (5.4) | 0.18% | — | IBM Langflow OSSAI | 14/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Pendiente de análisis | Media (6.5) | 0.22% | — | IBM Langflow OSSAI | 14/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.10.2 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Pendiente de análisis | Media (4.2) | 0.15% | — | IBM LangflowAIIBM Langflow OSSAI | 14/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context due to improper cache key isolation in the MCP Tools component. | |
| Pendiente de análisis | Media (5.4) | 0.34% | — | IBM Langflow OSSAI | 14/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to change the password of an account due to improper authentication. | |
| Analizada | Alta (8.8) | 0.85% | — | Langflow | 10/9/2026 | 14/9/2026 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory. | |
| Analizada | Alta (8.8) | 0.63% | — | Langflow | 10/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP Tools component configured to use a local stdio subprocess transport. This bypasses… | |
| Analizada | Alta (8.8) | 0.81% | — | Langflow | 10/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names. | |
| Analizada | Alta (8.1) | 0.43% | — | Langflow | 10/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation. | |
| Analizada | Alta (7.5) | 0.39% | — | Langflow | 10/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5. | |
| Analizada | Alta (8.6) | 0.49% | — | Langflow | 10/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of user-supplied URLs. | |
| Analizada | Alta (8.8) | 0.50% | — | Langflow | 10/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows. | |
| Analizada | Crítica (9.8) | 0.86% | — | Langflow | 10/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction. | |
| Analizada | Alta (8.8) | 0.81% | — | Langflow | 10/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist. | |
| Analizada | Media (6.5) | 0.41% | — | Langflow | 10/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to read arbitrary files due to improper access control. | |
| Analizada | Crítica (9.8) | 0.67% | — | Langflow | 10/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command. | |
| Analizada | Media (5) | 0.35% | — | Langflow | 10/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-controlled API endpoints. | |
| Analizada | Alta (8.8) | 0.79% | — | Langflow | 10/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the MCP stdio server configuration. | |
| Analizada | Alta (8.8) | 0.81% | — | Langflow | 10/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an unguarded eval() call on attacker-controlled input. | |
| Analizada | Alta (8.8) | 0.65% | — | Langflow | 10/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete denylist in the security scanner. | |
| Analizada | Alta (8.8) | 0.68% | — | Langflow | 10/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 An attacker who could submit custom component source code could bypass the static security scanner by crafting an annotated class-body assignment that resolved to a dangerous callable through alias tracking; the resolved value was never checked against the dangerous callable… |