VYPR

Langflow OSS

by IBM

Source repositories

CVEs (68)

  • CVE-2026-9198CriKEVJul 17, 2026
    risk 0.77cvss 9.8epss 0.37

    IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments

  • CVE-2026-10561CriJun 22, 2026
    risk 0.65cvss 10.0epss 0.01

    IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise

  • CVE-2026-7664CriJun 22, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.

  • CVE-2026-10140CriJun 30, 2026
    risk 0.62cvss 9.6epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. An authenticated attacker can manipulate cache state to cause requests from other users to be processed using incorrect upstream…

  • CVE-2026-19297CriAug 13, 2026
    risk 0.59cvss 9.1epss 0.00

    IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts.

  • CVE-2026-9201HigAug 5, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in the custom component validation mechanism. When the optional hardening mode that restricts execution to trusted component templates is…

  • CVE-2026-8478HigAug 5, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.

  • CVE-2026-8182HigAug 5, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any credentials via 2 HTTP requests.

  • CVE-2026-17632HigAug 5, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code during AST-based security scanning.

  • CVE-2026-17626HigAug 5, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Docker-based MCP servers due to incomplete filtering of dangerous Docker volume-mount and device-mapping arguments.

  • CVE-2026-17623HigAug 5, 2026
    risk 0.57cvss 8.8epss 0.01

    IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of the command field in MCP server configurations.

  • CVE-2026-7524CriMay 27, 2026
    risk 0.57cvss 9.8epss 0.01

    IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links during archive extraction.

  • CVE-2026-6543HigApr 30, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow allows an attacker to execute arbitrary commands with the privileges of the process running Langflow. This allows reading sensitive environment variables (API keys, DB credentials), modifying files, or launching further attacks…

  • CVE-2026-17633HigAug 5, 2026
    risk 0.55cvss 8.5epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injection.

  • CVE-2026-17624HigAug 5, 2026
    risk 0.55cvss 8.5epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of…

  • CVE-2026-9077HigAug 5, 2026
    risk 0.55cvss 8.5epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations to IDE configuration files on the host system.

  • CVE-2026-9196HigAug 5, 2026
    risk 0.53cvss 8.1epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to improper handling of LLM‑generated components. The application executes model‑generated Python code in the backend during…

  • CVE-2026-8183HigAug 5, 2026
    risk 0.50cvss 7.7epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request…

  • CVE-2026-19875HigAug 19, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email information and abuse the server as an outbound relay due to missing authentication for the registration endpoint.

  • CVE-2026-8446HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP) composer endpoint when mcp_composer_enabled=true (default) and projects are configured with auth_type=oauth .

Page 1 of 4