langflow-ai langflow

5 known vulnerabilities in langflow-ai langflow, 2 critical, 3 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2026-55255 CVSS 8.4 high · actively exploited Langflow Authorization Bypass Through User-Controlled Key Vulnerability
  • CVE-2026-33017 CVSS 9.3 critical · actively exploited Langflow Code Injection Vulnerability
  • CVE-2025-3248 CVSS 9.8 critical · actively exploited Langflow Missing Authentication Vulnerability

Latest vulnerabilities

  • CVE-2026-101861 CVSS 2.1 low Langflow 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() vulnerability in schema.py that allows authenticated…
  • CVE-2026-55255 CVSS 8.4 high · actively exploited Langflow Authorization Bypass Through User-Controlled Key Vulnerability
  • CVE-2026-5027 CVSS 8.8 high The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write…
  • CVE-2026-33017 CVSS 9.3 critical · actively exploited Langflow Code Injection Vulnerability
  • CVE-2025-3248 CVSS 9.8 critical · actively exploited Langflow Missing Authentication Vulnerability