langflow-ai langflow
5 known vulnerabilities in langflow-ai langflow, 2 critical, 3 actively exploited, with patch priority, exploit likelihood and the news covering them.
Recently exploited
- CVE-2026-55255 CVSS 8.4 high · actively exploited Langflow Authorization Bypass Through User-Controlled Key Vulnerability
- CVE-2026-33017 CVSS 9.3 critical · actively exploited Langflow Code Injection Vulnerability
- CVE-2025-3248 CVSS 9.8 critical · actively exploited Langflow Missing Authentication Vulnerability
Latest vulnerabilities
- CVE-2026-101861 CVSS 2.1 low Langflow 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() vulnerability in schema.py that allows authenticated…
- CVE-2026-55255 CVSS 8.4 high · actively exploited Langflow Authorization Bypass Through User-Controlled Key Vulnerability
- CVE-2026-5027 CVSS 8.8 high The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write…
- CVE-2026-33017 CVSS 9.3 critical · actively exploited Langflow Code Injection Vulnerability
- CVE-2025-3248 CVSS 9.8 critical · actively exploited Langflow Missing Authentication Vulnerability