Langflow
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 170 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from June 10, 2024 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Langflow: IP Spoofing Bypass via `X-Forwarded-For` Allowing Remote Configuration Write
Langflow: Authenticated RCE via MCP Stdio transport allows any user to execute arbitrary OS commands on the server
Langflow: Authenticated Cross-Project File Disclosure via Unscoped MCP Resource Handlers
Langflow: Cross-user flow access and vertex execution via deprecated /api/v1/build/{flow_id}/vertices endpoints
Langflow Code Execution via eval() in Component Input Schema
Sysdig documented the first fully autonomous AI ransomware campaign. JADEPUFFER breached Langflow, pivoted to Nacos, and corrected its own failed exploits in 31 seconds.
Langflow is vulnerable to unauthorized file system access due to path traversal and missing storage path validation
Langflow is vulnerable to unauthorized file system access due to path traversal and missing storage path validation
Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards
Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards
Monitor Langflow in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.