SecAlerts
L

Langflow

Security Risk Profile

59
/100
medium

Security Risk Score

Comprehensive risk assessment based on 170 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from June 10, 2024 to present

170
Total CVEs
129
Critical+High
10
Exploited
105
Unpatched

Threat Assessment

Avg CVSS
8.2
Base severity
Avg EPSS
5%
Exploit probability
Unpatched
105
Critical/High
Risk Level
59/100
medium
⚠️ 10 Active Exploits🆕 4Fresh (<7d)📈 24 in Last 30 Days

Severity Distribution

Critical
52
High
77
Medium
34
Low
2

Exploit Likelihood

>50% chance
2
20-50%
0
5-20%
0
<5%
30

Age Distribution

Common Weaknesses (CWE)

1
Code Injection
36
2
Path Traversal
27
3
SSRF
17
4
OS Command Injection
9
5
Input Validation
6

Most Affected Products

1. Langflow Langflow208
2. IBM Langflow OSS168
3. pip/langflow30
4. IBM Langflow Desktop14
5. IBM Langflow12

Recent Vulnerabilities

See more →
CVE-2026-105741
CVSS 7.1high

Langflow: IP Spoofing Bypass via `X-Forwarded-For` Allowing Remote Configuration Write

Oct 5, 2026🔧 No Patch
CVE-2026-105740
CVSS 9.9critical

Langflow: Authenticated RCE via MCP Stdio transport allows any user to execute arbitrary OS commands on the server

Oct 5, 2026🔧 No Patch
CVE-2026-105699
CVSS 7.1high

Langflow: Authenticated Cross-Project File Disclosure via Unscoped MCP Resource Handlers

Oct 5, 2026🔧 No Patch
CVE-2026-105698
CVSS 5.4medium

Langflow: Cross-user flow access and vertex execution via deprecated /api/v1/build/{flow_id}/vertices endpoints

Oct 5, 2026🔧 No Patch
CVE-2026-101861
CVSS 2.1low

Langflow Code Execution via eval() in Component Input Schema

Sep 28, 2026🔧 No Patch
https://reddit.com/r/Infosec/comments/1wlaks1/sysdig_documented_the_first_fully_autonomous_ai/
unknown

Sysdig documented the first fully autonomous AI ransomware campaign. JADEPUFFER breached Langflow, pivoted to Nacos, and corrected its own failed exploits in 31 seconds.

Sep 20, 2026🔧 No Patch
CVE-2026-9225
CVSS 6.5EPSS 0%medium

Langflow is vulnerable to unauthorized file system access due to path traversal and missing storage path validation

Sep 8, 2026🔧 No Patch
CVE-2026-79725
CVSS 6.5medium

Langflow is vulnerable to unauthorized file system access due to path traversal and missing storage path validation

Sep 8, 2026🔧 No Patch
CVE-2026-85025
CVSS 9.8critical

Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards

Sep 8, 2026🔧 No Patch
CVE-2026-76059
CVSS 8.8high

Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards

Sep 8, 2026🔧 No Patch

Monitor Langflow in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.