Langflow
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 147 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from June 10, 2024 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →A path traversal vulnerability in file handling components could allow an authenticated attacker to write files to arbitrary locations on the server filesystem
Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base components
Langflow is affected by improper authorization due to missing access control on the voice-mode WebSocket endpoint
Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base components
Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base components
Langflow is vulnerable to stored cross-site scripting and IP spoofing due to unsanitized Markdown rendering and untrusted proxy header trust
Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing components
Langflow is vulnerable to stored cross-site scripting and IP spoofing due to unsanitized Markdown rendering and untrusted proxy header trust
Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing components
Langflow is vulnerable to arbitrary local file read due to path traversal in ChatInput, bundle FileInput, and GitExtractor components
Monitor Langflow in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.