langflow
98 known vulnerabilities affecting langflow products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-0770 | Act now | 63.4% | 9.8 | ● | Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere R… |
| CVE-2026-9198 | Act now | 60.6% | 9.8 | ● | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain … |
| CVE-2026-5027 | Medium | 36.1% | 8.8 | The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter fro… | |
| CVE-2026-19295 | Medium | 1.8% | 9.9 | IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execut… | |
| CVE-2026-8476 | Medium | 1.0% | 9.9 | IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution v… | |
| CVE-2026-17623 | Medium | 1.0% | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacke… | |
| CVE-2026-18729 | Medium | 0.9% | 8.8 | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacke… | |
| CVE-2026-9135 | Medium | 0.8% | 9.9 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 9498… | |
| CVE-2026-8481 | Medium | 0.8% | 9.9 | IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution v… | |
| CVE-2026-17625 | Medium | 0.8% | 7.2 | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.… | |
| CVE-2026-81941 | Medium | 0.8% | 8.8 | IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative… | |
| CVE-2026-7755 | Medium | 0.7% | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution… | |
| CVE-2026-9103 | Medium | 0.7% | 9.8 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unau… | |
| CVE-2026-12940 | Medium | 0.7% | 9.8 | IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote … | |
| CVE-2026-13448 | Medium | 0.7% | 8.1 | IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated re… | |
| CVE-2026-14499 | Medium | 0.7% | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user… | |
| CVE-2026-19286 | Medium | 0.6% | 9.8 | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute a… | |
| CVE-2026-17632 | Medium | 0.6% | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacke… | |
| CVE-2026-81204 | Medium | 0.6% | 9.8 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute a… | |
| CVE-2026-8505 | Medium | 0.6% | 9.8 | IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook … | |
| CVE-2026-7667 | Medium | 0.6% | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create… | |
| CVE-2026-8859 | Medium | 0.6% | 9.9 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write … | |
| CVE-2026-78571 | Medium | 0.6% | 8.8 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacke… | |
| CVE-2026-79742 | Medium | 0.6% | 8.8 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacke… | |
| CVE-2026-81940 | Medium | 0.6% | 8.8 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacke… | |
| CVE-2026-84889 | Medium | 0.5% | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacke… | |
| CVE-2026-8056 | Medium | 0.5% | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override com… | |
| CVE-2026-8635 | Medium | 0.5% | 9.9 | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate pri… | |
| CVE-2026-78575 | Medium | 0.5% | 8.8 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacke… | |
| CVE-2026-9202 | Medium | 0.5% | 9.8 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create… | |
| CVE-2026-19298 | Medium | 0.5% | 8.8 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacke… | |
| CVE-2026-76059 | Medium | 0.5% | 8.8 | IBM Langflow OSS 1.0.0 through 1.11.5 An attacker who could submit custom compon… | |
| CVE-2026-79724 | Medium | 0.5% | 9.8 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute a… | |
| CVE-2026-3357 | Medium | 0.5% | 8.8 | IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated u… | |
| CVE-2026-18899 | Medium | 0.5% | 7.5 | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbi… | |
| CVE-2026-78569 | Medium | 0.5% | 8.8 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to e… | |
| CVE-2026-85025 | Medium | 0.4% | 9.8 | IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated at… | |
| CVE-2026-17630 | Medium | 0.4% | 7.2 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute a… | |
| CVE-2026-19297 | Medium | 0.4% | 9.1 | IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain una… | |
| CVE-2026-12942 | Medium | 0.4% | 7.5 | IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse … | |
| CVE-2026-19306 | Medium | 0.4% | 7.7 | IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read a… | |
| CVE-2026-17633 | Medium | 0.4% | 8.5 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacke… | |
| CVE-2026-19303 | Medium | 0.4% | 8.1 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacke… | |
| CVE-2026-17624 | Medium | 0.4% | 8.5 | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.… | |
| CVE-2026-8182 | Medium | 0.4% | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet… | |
| CVE-2026-13446 | Medium | 0.4% | 9.8 | IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a… | |
| CVE-2026-8478 | Medium | 0.4% | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject ar… | |
| CVE-2026-19300 | Medium | 0.4% | 7.5 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain se… | |
| CVE-2026-8183 | Medium | 0.4% | 7.7 | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.… | |
| CVE-2026-19875 | Medium | 0.4% | 7.5 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite… |
Page 1 of 2
Next →