Langflow
Langflow: vulnerabilidades y CVE
Langflow tiene 161 vulnerabilidades publicadas, 154 de ellas en los últimos 12 meses. 50 son críticas y 6 figuran en el catálogo de explotación activa de CISA.
CVE161
Últimos 12 meses154
Críticas50
Explotadas activamente6
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-9198 | Crítica (9.8) | 29% | ⚠ Explotación activa | 17 jul 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve… |
| CVE-2026-0770 | Crítica (9.8) | 64% | ⚠ Explotación activa | 23 ene 2026 | Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of… |
| CVE-2026-55255 | Alta (8.4) | 0.89% | ⚠ Explotación activa | 23 jun 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to… |
| CVE-2025-34291 | Crítica (9.4) | 93% | ⚠ Explotación activa | 5 dic 2025 | Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with… |
| CVE-2026-33017 | Crítica (9.3) | 25% | ⚠ Explotación activa | 20 mar 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring… |
| CVE-2025-3248 | Crítica (9.8) | 100% | ⚠ Explotación activa | 7 abr 2025 | Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-101861 | Baja (2.1) | 0.20% | — | 28 sept 2026 | Langflow 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() vulnerability in schema.py that allows authenticated attackers to achieve code execution by placing a Python object with a malicious… |
| CVE-2026-84889 | Alta (8.8) | 0.85% | — | 10 sept 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory. |
| CVE-2026-81941 | Alta (8.8) | 0.63% | — | 10 sept 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a… |
| CVE-2026-81940 | Alta (8.8) | 0.81% | — | 10 sept 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names. |
| CVE-2026-81268 | Alta (8.1) | 0.43% | — | 10 sept 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation. |
| CVE-2026-81265 | Alta (7.5) | 0.39% | — | 10 sept 2026 | IBM Langflow OSS 1.0.0 through 1.11.5. |
| CVE-2026-81213 | Alta (8.6) | 0.49% | — | 10 sept 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of user-supplied URLs. |
| CVE-2026-81211 | Alta (8.8) | 0.50% | — | 10 sept 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows. |
| CVE-2026-81204 | Crítica (9.8) | 0.86% | — | 10 sept 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction. |
| CVE-2026-79742 | Alta (8.8) | 0.81% | — | 10 sept 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist. |
| CVE-2026-79725 | Media (6.5) | 0.41% | — | 10 sept 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to read arbitrary files due to improper access control. |
| CVE-2026-79724 | Crítica (9.8) | 0.67% | — | 10 sept 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command. |
| CVE-2026-79723 | Media (5) | 0.35% | — | 10 sept 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-controlled API endpoints. |
| CVE-2026-78575 | Alta (8.8) | 0.79% | — | 10 sept 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the MCP stdio server configuration. |
| CVE-2026-78571 | Alta (8.8) | 0.81% | — | 10 sept 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an unguarded eval() call on attacker-controlled input. |
| CVE-2026-78569 | Alta (8.8) | 0.65% | — | 10 sept 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete denylist in the security scanner. |
| CVE-2026-76059 | Alta (8.8) | 0.68% | — | 10 sept 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 An attacker who could submit custom component source code could bypass the static security scanner by crafting an annotated class-body assignment that resolved to a dangerous… |
| CVE-2026-9225 | Media (6.5) | 0.35% | — | 10 sept 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an authenticated attacker to access sensitive files belonging to other users due to improper access control in the File/Read File component. When executing… |
| CVE-2026-85025 | Crítica (9.8) | 0.61% | — | 10 sept 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper… |
| CVE-2026-17631 | Media (6.5) | 0.23% | — | 4 sept 2026 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability. |
| CVE-2026-17627 | Alta (7.1) | 0.20% | — | 4 sept 2026 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information and inject messages into workflow history due to improper authorization. |
| CVE-2026-17622 | Media (6.5) | 0.49% | — | 4 sept 2026 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory. |
| CVE-2026-17621 | Media (5.4) | 0.29% | — | 4 sept 2026 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view… |
| CVE-2026-14470 | Media (6.5) | 0.34% | — | 4 sept 2026 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view… |
| CVE-2026-19306 | Alta (7.7) | 0.40% | — | 4 sept 2026 | IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JWT signing keys, the application database,… |
| CVE-2026-19305 | Alta (7.5) | 0.29% | — | 4 sept 2026 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery. |
| CVE-2026-19304 | Alta (7.7) | 0.31% | — | 4 sept 2026 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information from internal services due to a URL parser discrepancy. |
| CVE-2026-19303 | Alta (8.1) | 0.40% | — | 4 sept 2026 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrary local files or directories due to improper limitation of a pathname to a restricted directory. |
| CVE-2026-19302 | Media (6.5) | 0.49% | — | 4 sept 2026 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links. |
| CVE-2026-19301 | Media (6.5) | 0.29% | — | 4 sept 2026 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.