Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-21445

63
FAUCET Score

CVE-2026-21445 is a critical authentication bypass vulnerability affecting Langflow versions prior to 1.7.0.dev45. Unauthenticated attackers can access sensitive user conversation data, transaction histories, and perform destructive operations like message deletion due to missing authentication controls on multiple API endpoints. With a CVSS score of 9.1 (CRITICAL), this network-exploitable flaw requires no user interaction and can lead to high confidentiality, integrity, and availability impacts. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion, but a patch is available in version 1.7.0.dev45.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.7.1CPE matchmatch criteria
cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.8HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
34.07%
Probability of exploitation in next 30 days
EPSS Percentile
98.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Nuclei: CVE-2026-21445 · Mar 25, 2026
This CVE's current EPSS score of 0.3407 is in the 95th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: langflow-baseFixed in: 0.7.1
pippatch availablevia ghsa
Product: langflowFixed in: 1.7.1

Vendor Advisories (1)

pipGHSA-c5cp-vx83-jhqxhigh

Langflow Missing Authentication on Critical API Endpoints

Jan 2, 2026

References

github.com / langflow-ai/langflow/commit/3fed9fe1b5658f2c8656dbd73508e113a96e486a
Patch
github.com / langflow-ai/langflow/security/advisories/GHSA-c5cp-vx83-jhqx
ExploitVendor Advisory