SecAlerts
L

Langflow

Security Risk Profile

59
/100
medium

Security Risk Score

Comprehensive risk assessment based on 147 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from June 10, 2024 to present

147
Total CVEs
112
Critical+High
10
Exploited
91
Unpatched

Threat Assessment

Avg CVSS
8.2
Base severity
Avg EPSS
5%
Exploit probability
Unpatched
91
Critical/High
Risk Level
59/100
medium
⚠️ 10 Active Exploits📈 26 in Last 30 Days

Severity Distribution

Critical
48
High
64
Medium
30
Low
1

Exploit Likelihood

>50% chance
2
20-50%
0
5-20%
0
<5%
29

Age Distribution

Common Weaknesses (CWE)

1
Code Injection
31
2
Path Traversal
26
3
SSRF
14
4
Input Validation
6
5
OS Command Injection
5

Most Affected Products

1. Langflow Langflow185
2. IBM Langflow OSS150
3. pip/langflow27
4. IBM Langflow Desktop14
5. IBM Langflow12

Recent Vulnerabilities

See more →
CVE-2026-84889
CVSS 8.8high

A path traversal vulnerability in file handling components could allow an authenticated attacker to write files to arbitrary locations on the server filesystem

Sep 8, 2026🔧 No Patch
CVE-2026-17622
CVSS 6.5medium

Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base components

Sep 3, 2026🔧 No Patch
CVE-2026-17627
CVSS 7.1high

Langflow is affected by improper authorization due to missing access control on the voice-mode WebSocket endpoint

Sep 3, 2026🔧 No Patch
CVE-2026-17621
CVSS 5.4medium

Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base components

Sep 3, 2026🔧 No Patch
CVE-2026-14470
CVSS 6.5medium

Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base components

Sep 3, 2026🔧 No Patch
CVE-2026-8447
CVSS 6.1medium

Langflow is vulnerable to stored cross-site scripting and IP spoofing due to unsanitized Markdown rendering and untrusted proxy header trust

Aug 28, 2026🔧 No Patch
CVE-2026-9138
CVSS 6.5EPSS 0%medium

Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing components

Aug 28, 2026🔧 No Patch
CVE-2026-9186
CVSS 6.5EPSS 0%medium

Langflow is vulnerable to stored cross-site scripting and IP spoofing due to unsanitized Markdown rendering and untrusted proxy header trust

Aug 28, 2026🔧 No Patch
CVE-2026-19303
CVSS 8.1high

Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing components

Aug 28, 2026🔧 No Patch
CVE-2026-19306
CVSS 7.7high

Langflow is vulnerable to arbitrary local file read due to path traversal in ChatInput, bundle FileInput, and GitExtractor components

Aug 28, 2026🔧 No Patch

Monitor Langflow in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.