SecAlerts
Langflow logo

Langflow

Security Risk Profile

65
/100
high

Security Risk Score

Comprehensive risk assessment based on 87 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from June 10, 2024 to present

87
Total CVEs
70
Critical+High
8
Exploited
49
Unpatched

Threat Assessment

Avg CVSS
8.6
Base severity
Avg EPSS
4%
Exploit probability
Unpatched
49
Critical/High
Risk Level
65/100
high
⚠️ 8 Active Exploits📈 5 in Last 30 Days

Severity Distribution

Critical
40
High
30
Medium
12
Low
1

Exploit Likelihood

>50% chance
1
20-50%
0
5-20%
0
<5%
22

Age Distribution

Common Weaknesses (CWE)

1
Code Injection
20
2
Path Traversal
11
3
SSRF
7
4
Input Validation
4
5
OS Command Injection
2

Most Affected Products

1. Langflow Langflow124
2. IBM Langflow OSS62
3. pip/langflow27
4. IBM Langflow Desktop14
5. Langflow Langflow Desktop7

Recent Vulnerabilities

See more →
CVE-2026-13448
CVSS 9.8critical

Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints

7/14/2026🔧 No Patch
CVE-2026-14499
CVSS 8.8high

Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints

7/14/2026🔧 No Patch
CVE-2026-13445
CVSS 8.1high

Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints

7/14/2026🔧 No Patch
CVE-2026-13446
CVSS 9.8critical

Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints

7/14/2026🔧 No Patch
bleepingcomputer-20260708095811
unknown

CISA orders feds to prioritize patching Langflow auth bypass flaw

7/8/2026⚠ Exploited🔧 No Patch
CVE-2026-9202
CVSS 9.8EPSS 0%critical

Unauthenticated User Registration Could Lead to Remote Code Execution

7/2/2026🔧 No Patch
CVE-2026-9198
CVSS 9.8EPSS 2%critical

Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation

7/2/2026🔧 No Patch
CVE-2026-9103
CVSS 9.8EPSS 0%critical

Unauthenticated Superuser Token Issuance via Auto-Login Endpoint

7/2/2026🔧 No Patch
CVE-2026-9135
CVSS 9.9EPSS 0%critical

Policies Component Dynamic CodeInput Fields Bypass Custom Component Validation

7/2/2026🔧 No Patch
CVE-2026-7667
CVSS 8.8high

Path Traversal Vulnerability in API Request Component Content-Disposition Header Processing

7/2/2026🔧 No Patch

Monitor Langflow in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

Langflow Security Vulnerabilities & Risk Score | 87 CVEs | SecAlerts - SecAlerts