CVE-2025-68477 describes a Server-Side Request Forgery (SSRF) vulnerability in Langflow, a tool for building AI agents, affecting versions prior to 1.7.0. The API Request component in Langflow allows unauthenticated users to supply arbitrary URLs, leading to requests to internal network resources and cloud metadata endpoints. This medium-severity vulnerability (CVSS 6.5) has a low attack complexity and can result in significant information disclosure from internal administrative endpoints and databases. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.7.0CPE matchmatch criteria | cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.