« Volver al listado

Langflow

Langflow: vulnerabilidades y CVE

Langflow tiene 161 vulnerabilidades publicadas, 154 de ellas en los últimos 12 meses. 50 son críticas y 6 figuran en el catálogo de explotación activa de CISA.

CVE161
Últimos 12 meses154
Críticas50
Explotadas activamente6

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-9198Crítica (9.8)29%⚠ Explotación activa17 jul 2026
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve…
CVE-2026-0770Crítica (9.8)64%⚠ Explotación activa23 ene 2026
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of…
CVE-2026-55255Alta (8.4)0.89%⚠ Explotación activa23 jun 2026
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to…
CVE-2025-34291Crítica (9.4)93%⚠ Explotación activa5 dic 2025
Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with…
CVE-2026-33017Crítica (9.3)25%⚠ Explotación activa20 mar 2026
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring…
CVE-2025-3248Crítica (9.8)100%⚠ Explotación activa7 abr 2025
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-101861Baja (2.1)0.20%—28 sept 2026
Langflow 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() vulnerability in schema.py that allows authenticated attackers to achieve code execution by placing a Python object with a malicious…
CVE-2026-84889Alta (8.8)0.85%—10 sept 2026
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.
CVE-2026-81941Alta (8.8)0.63%—10 sept 2026
IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a…
CVE-2026-81940Alta (8.8)0.81%—10 sept 2026
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names.
CVE-2026-81268Alta (8.1)0.43%—10 sept 2026
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation.
CVE-2026-81265Alta (7.5)0.39%—10 sept 2026
IBM Langflow OSS 1.0.0 through 1.11.5.
CVE-2026-81213Alta (8.6)0.49%—10 sept 2026
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of user-supplied URLs.
CVE-2026-81211Alta (8.8)0.50%—10 sept 2026
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows.
CVE-2026-81204Crítica (9.8)0.86%—10 sept 2026
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction.
CVE-2026-79742Alta (8.8)0.81%—10 sept 2026
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist.
CVE-2026-79725Media (6.5)0.41%—10 sept 2026
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to read arbitrary files due to improper access control.
CVE-2026-79724Crítica (9.8)0.67%—10 sept 2026
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.
CVE-2026-79723Media (5)0.35%—10 sept 2026
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-controlled API endpoints.
CVE-2026-78575Alta (8.8)0.79%—10 sept 2026
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the MCP stdio server configuration.
CVE-2026-78571Alta (8.8)0.81%—10 sept 2026
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an unguarded eval() call on attacker-controlled input.
CVE-2026-78569Alta (8.8)0.65%—10 sept 2026
IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete denylist in the security scanner.
CVE-2026-76059Alta (8.8)0.68%—10 sept 2026
IBM Langflow OSS 1.0.0 through 1.11.5 An attacker who could submit custom component source code could bypass the static security scanner by crafting an annotated class-body assignment that resolved to a dangerous…
CVE-2026-9225Media (6.5)0.35%—10 sept 2026
IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an authenticated attacker to access sensitive files belonging to other users due to improper access control in the File/Read File component. When executing…
CVE-2026-85025Crítica (9.8)0.61%—10 sept 2026
IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper…
CVE-2026-17631Media (6.5)0.23%—4 sept 2026
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability.
CVE-2026-17627Alta (7.1)0.20%—4 sept 2026
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information and inject messages into workflow history due to improper authorization.
CVE-2026-17622Media (6.5)0.49%—4 sept 2026
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
CVE-2026-17621Media (5.4)0.29%—4 sept 2026
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view…
CVE-2026-14470Media (6.5)0.34%—4 sept 2026
IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view…
CVE-2026-19306Alta (7.7)0.40%—4 sept 2026
IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JWT signing keys, the application database,…
CVE-2026-19305Alta (7.5)0.29%—4 sept 2026
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery.
CVE-2026-19304Alta (7.7)0.31%—4 sept 2026
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information from internal services due to a URL parser discrepancy.
CVE-2026-19303Alta (8.1)0.40%—4 sept 2026
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrary local files or directories due to improper limitation of a pathname to a restricted directory.
CVE-2026-19302Media (6.5)0.49%—4 sept 2026
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.
CVE-2026-19301Media (6.5)0.29%—4 sept 2026
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter5
  2. T1190 Exploit Public-Facing Application4
  3. T1078.001 Default Accounts1
  4. T1203 Exploitation for Client Execution1
  5. T1210 Exploitation of Remote Services1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Langflow