Langflow OSS
by IBM
Source repositories
CVEs (141)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-9198 | Cri | 0.77 | 9.8 | 0.29 | KEV | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments | |
| CVE-2026-93674 | Cri | 0.64 | 9.8 | 0.01 | Oct 7, 2026 | IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | ||
| CVE-2026-104334 | Cri | 0.64 | 9.8 | 0.01 | Oct 7, 2026 | IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper control of code generation. | ||
| CVE-2026-81204 | Cri | 0.64 | 9.8 | 0.01 | Sep 10, 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction. | ||
| CVE-2026-79724 | Cri | 0.64 | 9.8 | 0.01 | Sep 10, 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command. | ||
| CVE-2026-85025 | Cri | 0.64 | 9.8 | 0.01 | Sep 10, 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow security restrictions and session… | ||
| CVE-2026-7664 | Cri | 0.64 | 9.8 | 0.01 | Jun 22, 2026 | IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint. | ||
| CVE-2026-12944 | Cri | 0.62 | 9.6 | 0.00 | Sep 14, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential theft via IMDSv1 SSRF with full IAM role… | ||
| CVE-2026-10140 | Cri | 0.62 | 9.6 | 0.00 | Jun 30, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. An authenticated attacker can manipulate cache state to cause requests from other users to be processed using incorrect upstream… | ||
| CVE-2026-19297 | Cri | 0.59 | 9.1 | 0.01 | Aug 13, 2026 | IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts. | ||
| CVE-2026-10561 | Cri | 0.58 | 10.0 | 0.01 | Jun 22, 2026 | IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise | ||
| CVE-2026-93675 | Hig | 0.57 | 8.8 | 0.01 | Oct 7, 2026 | IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to an expected dependency confusion. | ||
| CVE-2026-88962 | Hig | 0.57 | 8.8 | 0.01 | Oct 7, 2026 | IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of code generation. | ||
| CVE-2026-104335 | Hig | 0.57 | 8.8 | 0.01 | Oct 7, 2026 | IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper access control. | ||
| CVE-2026-84889 | Hig | 0.57 | 8.8 | 0.01 | Sep 10, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory. | ||
| CVE-2026-81941 | Hig | 0.57 | 8.8 | 0.01 | Sep 10, 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP Tools component configured to use a local… | ||
| CVE-2026-81211 | Hig | 0.57 | 8.8 | 0.01 | Sep 10, 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows. | ||
| CVE-2026-79742 | Hig | 0.57 | 8.8 | 0.01 | Sep 10, 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist. | ||
| CVE-2026-78575 | Hig | 0.57 | 8.8 | 0.01 | Sep 10, 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the MCP stdio server configuration. | ||
| CVE-2026-78569 | Hig | 0.57 | 8.8 | 0.01 | Sep 10, 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete denylist in the security scanner. |
- risk 0.77cvss 9.8epss 0.29
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments
- risk 0.64cvss 9.8epss 0.01
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
- risk 0.64cvss 9.8epss 0.01
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper control of code generation.
- risk 0.64cvss 9.8epss 0.01
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction.
- risk 0.64cvss 9.8epss 0.01
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.
- risk 0.64cvss 9.8epss 0.01
IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow security restrictions and session…
- risk 0.64cvss 9.8epss 0.01
IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.
- risk 0.62cvss 9.6epss 0.00
IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential theft via IMDSv1 SSRF with full IAM role…
- risk 0.62cvss 9.6epss 0.00
IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. An authenticated attacker can manipulate cache state to cause requests from other users to be processed using incorrect upstream…
- risk 0.59cvss 9.1epss 0.01
IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts.
- risk 0.58cvss 10.0epss 0.01
IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise
- risk 0.57cvss 8.8epss 0.01
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to an expected dependency confusion.
- risk 0.57cvss 8.8epss 0.01
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of code generation.
- risk 0.57cvss 8.8epss 0.01
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper access control.
- risk 0.57cvss 8.8epss 0.01
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.
- risk 0.57cvss 8.8epss 0.01
IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP Tools component configured to use a local…
- risk 0.57cvss 8.8epss 0.01
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows.
- risk 0.57cvss 8.8epss 0.01
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist.
- risk 0.57cvss 8.8epss 0.01
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the MCP stdio server configuration.
- risk 0.57cvss 8.8epss 0.01
IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete denylist in the security scanner.
Page 1 of 8