CVE-2024-42835: Critical severity Langflow Langflow vulnerability
Published Oct 31, 2024
·Updated
langflow v1.0.12 was discovered to contain a remote code execution (RCE) vulnerability via the PythonCodeTool component.
Affected Software
2 affected components
pip/langflow<=1.0.12
Langflow Langflow=1.0.12
Event History
Oct 31, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverity
Advisory Published
via GitHub·03:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-42835?
CVE-2024-42835 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2024-42835?
To fix CVE-2024-42835, upgrade langflow to a version later than 1.0.12.
3
What component of langflow is affected by CVE-2024-42835?
CVE-2024-42835 affects the PythonCodeTool component of langflow.
4
Can CVE-2024-42835 be exploited remotely?
Yes, CVE-2024-42835 is a remote code execution vulnerability that can be exploited by attackers.
5
What versions of langflow are impacted by CVE-2024-42835?
Versions of langflow up to and including 1.0.12 are impacted by CVE-2024-42835.