Langflow is a low-volume but prominently tracked open-source platform for building and deploying large-language-model applications, where its concentrated vulnerability footprint reflects the framework's exposure to code composition, file handling, and access-control operations. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit tooling, with a moderate tendency toward confirmed in-the-wild exploitation and CISA cataloging. The exposure recurs across authentication and authorization boundaries—including code injection, path traversal, authorization bypass through user-controlled keys, and missing authentication on critical functions—reflecting the inherent risks of a system that orchestrates dynamic LLM workflows and file I/O at scale. Defenders deploying Langflow should prioritize patching and restrict instance exposure; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Langflow over time
Signals from CVEs in this vendor scope (80 CVEs).
80 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33017CRITICAL Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building | Mar 20, 2026 | 9.8 | 99 | YES | YES |
CVE-2025-3248CRITICAL Langflow versions prior to 1.3.0 are susceptible to code injection in
the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to e | Apr 7, 2025 | 9.8 | 99 | YES | YES |
CVE-2026-0770CRITICAL Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary | Jan 23, 2026 | 9.8 | 97 | YES | YES |
CVE-2025-34291HIGH Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_ | Dec 5, 2025 | 8.8 | 97 | YES | YES |
CVE-2026-55255HIGH Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoin | Jun 23, 2026 | 8.4 | 81 | YES | NO |
CVE-2026-27966CRITICAL Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent node in Langflow hardcodes `allow_dangerous_code=True`, which a | Feb 26, 2026 | 9.8 | 66 | NO | YES |
CVE-2026-21445CRITICAL Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0.dev45, multiple critical API endpoints in Langflow are missing authentication | Jan 2, 2026 | 9.1 | 55 | NO | YES |
CVE-2026-0769CRITICAL Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installatio | Jan 23, 2026 | 9.8 | 49 | NO | NO |
CVE-2026-33497HIGH Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.1, in the download_profile_picture function of the /profile_pictures/{folder_nam | Mar 24, 2026 | 7.5 | 47 | NO | YES |
CVE-2026-9135CRITICAL IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies compone | Jul 17, 2026 | 9.9 | 43 | NO | NO |
Signals from CVEs in this vendor scope (80 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Langflow.
Media articles that mention a CVE ID that affects a product developed by Langflow — matched by CVE ID, not by vendor name.