langflow-base
PyPI7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting langflow-basepage 1 of 1
- CVE-2025-3248CRITICALCVSS 9.8EG 9.8⚠ KEVfixed in 0.3.02025-04-07
vulnerable: 0.0.13 ... 0.2.0 (93 versions)
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
- CVE-2025-57760HIGHCVSS 8.8EG 8.8fixed in 0.5.12025-08-25
vulnerable: 0.0.13 ... 0.5.0.post2 (105 versions)
Langflow is a tool for building and deploying AI-powered agents and workflows. A privilege escalation vulnerability exists in Langflow containers where an authenticated user with RCE access can invoke the internal CLI command langflow supe…
- CVE-2026-105697CRITICALCVSS 9.9EG 9.9fixed in 0.10.32026-10-05
vulnerable: 0.1.2 ... 0.9.6rc0 (62 versions)
Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP stdio transport launched whatever command / args a user put in an MCP server configuration, with no allowlist and (before 1.10.3…
- CVE-2026-105698MEDIUMCVSS 5.4EG 5.4fixed in 0.10.12026-10-05
vulnerable: 0.0.13 ... 0.9.6rc0 (146 versions)
Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.0.0 until 1.10.1, Langflow did not verify flow ownership in the deprecated POST /api/v1/build/{flow_id}/vertices and POST /api/v1/build/{flow_id}/vertice…
- CVE-2026-21445CRITICALCVSS 9.1EG 9.1fixed in 0.7.12026-01-02
vulnerable: 0.0.13 ... 0.7.0 (117 versions)
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0.dev45, multiple critical API endpoints in Langflow are missing authentication controls. The issue allows any unauthenticated user to acce…
- CVE-2026-34046HIGHCVSS 8.8EG 8.8fixed in 0.5.12026-03-27
vulnerable: 0.0.13 ... 0.5.0.post2 (105 versions)
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.5.1, the `_read_flow` helper in `src/backend/base/langflow/api/v1/flows.py` branched on the `AUTO_LOGIN` setting to decide whether to filter …
- CVE-2026-6596HIGHCVSS 7.3EG 7.3fixed in 0.9.12026-04-20
vulnerable: 0.0.13 ... 0.9.0 (134 versions)
A security flaw has been discovered in langflow-ai langflow up to 1.1.0. This issue affects the function create_upload_file of the file src/backend/base/Langflow/api/v1/endpoints.py of the component API Endpoint. The manipulation results i…
Check whether langflow-base is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for langflow-base CVEs against the assets you own.
Book a Demo →