Critical severity9.8NVD Advisory· Published Jun 10, 2024· Updated Jun 17, 2026
CVE-2024-37014
CVE-2024-37014
Description
Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and provide a Python script.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
langflowPyPI | < 1.0.15 | 1.0.15 |
Affected products
3cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*range: <=0.6.19
- (no CPE)
Patches
Vulnerability mechanics
References
4- github.com/langflow-ai/langflow/issues/1973nvdExploitIssue TrackingWEB
- github.com/advisories/GHSA-qg33-x2c5-6p44ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-37014ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/langflow/PYSEC-2024-177.yamlghsaWEB
News mentions
0No linked articles in our index yet.