Where
-Infinity
0

IBM Langflow OSSLangflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints

Risk 86
Severity
9.8
First published (updated )

IBM Langflow OSSLangflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints

Risk 79
Severity
8.8
First published (updated )

IBM Langflow OSSLangflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints

Risk 60
Severity
8.1
First published (updated )

IBM Langflow OSSLangflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints

Risk 86
Severity
9.8
First published (updated )

IBM Langflow OSSUnauthenticated User Registration Could Lead to Remote Code Execution

Risk 61
Severity
9.8
EPSS
0.28%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

IBM LangflowUnauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation

Risk 61
Severity
9.8
EPSS
1.89%
First published (updated )

IBM Langflow OSSUnauthenticated Superuser Token Issuance via Auto-Login Endpoint

Risk 61
Severity
9.8
EPSS
0.41%
First published (updated )

IBM Langflow OSSPolicies Component Dynamic CodeInput Fields Bypass Custom Component Validation

Risk 59
Severity
9.9
EPSS
0.45%
First published (updated )

IBM Langflow OSSPath Traversal Vulnerability in API Request Component Content-Disposition Header Processing

Risk 79
Severity
8.8
First published (updated )

IBM Langflow OSSPath Traversal Vulnerability in File Component Leading to Arbitrary File Read and Authentication Bypass

Risk 60
Severity
8.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

IBM Langflow OSSArbitrary Code Execution in Python Interpreter Component

Risk 82
Severity
9.9
First published (updated )

IBM Langflow OSSDisk Cache Deserialization Remote Code Execution Vulnerability

Risk 82
Severity
9.9
First published (updated )

IBM Langflow OSSRemote Code Execution via Code Validation Endpoint

Risk 82
Severity
9.9
First published (updated )

IBM Langflow OSSSSRF Protection Configuration Vulnerability

Risk 44
Severity
7.7
First published (updated )

IBM Langflow OSSAuthentication Bypass in Webhook Endpoints Allowed Unauthorized Flow Execution

Risk 86
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

IBM Langflow OSSMCP Server Configuration Validator Bypass via File Upload API

Risk 79
Severity
8.8
First published (updated )

IBM Langflow OSSPath Traversal in APIRequest Component via Content-Disposition Header

Risk 59
Severity
9.9
EPSS
0.37%
First published (updated )

IBM Langflow OSSParameter Injection Vulnerability in API Graph Execution Engine

Risk 79
Severity
8.8
First published (updated )

IBM Langflow OSSWeak Cryptographic Key Derivation Exposed All Stored Credentials

Risk 66
Severity
9.1
First published (updated )

IBM Langflow OSSInsecure Deserialization in Redis Cache Backend

Risk 86
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

IBM Langflow OSSFlow Validation Bypass via Empty Component Type Field

Risk 86
Severity
9.8
First published (updated )

IBM Langflow OSSCode Injection Vulnerability in Code Validation Endpoint

Risk 82
Severity
9.9
First published (updated )

IBM Langflow OSSCross-Tenant API Key Reuse and Billing Fraud in Langflow Voice Mode Subsystem

Risk 68
Severity
9.6
First published (updated )

IBM Langflow OSSSSRF Vulnerability in Langflow OSS Legacy Components Bypasses Protection

Risk 54
Severity
8.2
First published (updated )

IBM Langflow OSSUnauthenticated Access to Private Flow Build Events and Cancellation in Langflow OSS

Risk 66
Severity
9.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

IBM LangflowUnauthenticated Cross-User MCP Resource Access and Tool Execution via Streamable Transport Authorization Bypass

Risk 86
Severity
9.8
First published (updated )

IBM Langflow OSSSSRF via HTTP Redirect Following in Langflow API Request Component

Risk 55
Severity
8.5
First published (updated )

IBM Langflow OSSDNS Rebinding TOCTOU Bypass of SSRF Protection in Langflow OSS URL Component

Risk 48
Severity
7.1
First published (updated )

Langflow OSSUnauthenticated Server-Side RCE via PythonCodeStructuredTool in Public Flows

Risk 87
Severity
10
First published (updated )

pypi/langflowlangflow-ai langflow Bundle URL Loader code injection

Risk 69
Severity
1.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203