{"schema_version":1,"title":"Langflow vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 76 vulnerabilities in Langflow: 0 in the last 7 days and 51 in the last 90 days, 18 of them critical and 5 exploited in the wild. The most recent, CVE-2026-84889, was published on 10 September 2026.","url":"https://junglewise.ai/threats/technologies/langflow","json_url":"https://junglewise.ai/threats/technologies/langflow.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/langflow","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":36,"all_time":76,"critical":18,"exploited":5,"last_7_days":0,"last_30_days":43,"last_90_days":51,"last_365_days":75},"latest":[{"cve":"CVE-2026-84889","cvss":8.8,"epss":0.0085,"slug":"cve-2026-84889-ibm-langflow-oss-path-traversal-arbitrary-file-write","title":"IBM Langflow OSS path traversal arbitrary file write","severity":"high","exploited":false,"published_at":"2026-09-10T22:17:04.347+00:00","url":"https://junglewise.ai/threats/cve-2026-84889-ibm-langflow-oss-path-traversal-arbitrary-file-write"},{"cve":"CVE-2026-81941","cvss":8.8,"epss":0.0063,"slug":"cve-2026-81941-ibm-langflow-oss-privilege-escalation-in-mcp-tools-component","title":"IBM Langflow OSS privilege escalation in MCP Tools component","severity":"high","exploited":false,"published_at":"2026-09-10T22:17:03.22+00:00","url":"https://junglewise.ai/threats/cve-2026-81941-ibm-langflow-oss-privilege-escalation-in-mcp-tools-component"},{"cve":"CVE-2026-81940","cvss":8.8,"epss":0.0081,"slug":"cve-2026-81940-ibm-langflow-oss-code-injection-in-flow-display-names","title":"IBM Langflow OSS code injection in flow display names","severity":"high","exploited":false,"published_at":"2026-09-10T22:17:03.083+00:00","url":"https://junglewise.ai/threats/cve-2026-81940-ibm-langflow-oss-code-injection-in-flow-display-names"},{"cve":"CVE-2026-81268","cvss":8.1,"epss":0.0043,"slug":"cve-2026-81268-ibm-langflow-oss-insufficient-api-key-session-expiration","title":"IBM Langflow OSS insufficient API key session expiration","severity":"high","exploited":false,"published_at":"2026-09-10T22:17:02.39+00:00","url":"https://junglewise.ai/threats/cve-2026-81268-ibm-langflow-oss-insufficient-api-key-session-expiration"},{"cve":"CVE-2026-81265","cvss":7.5,"epss":0.0039,"slug":"cve-2026-81265-ibm-langflow-oss-server-side-request-forgery-via-url-validation","title":"IBM Langflow OSS server-side request forgery via URL validation bypass","severity":"high","exploited":false,"published_at":"2026-09-10T22:17:02.253+00:00","url":"https://junglewise.ai/threats/cve-2026-81265-ibm-langflow-oss-server-side-request-forgery-via-url-validation"},{"cve":"CVE-2026-81213","cvss":8.6,"epss":0.0049,"slug":"cve-2026-81213-ibm-langflow-server-side-request-forgery-in-url-validation","title":"IBM Langflow server-side request forgery in URL validation","severity":"high","exploited":false,"published_at":"2026-09-10T22:17:02.11+00:00","url":"https://junglewise.ai/threats/cve-2026-81213-ibm-langflow-server-side-request-forgery-in-url-validation"},{"cve":"CVE-2026-81211","cvss":8.8,"epss":0.005,"slug":"cve-2026-81211-ibm-langflow-arbitrary-code-execution-in-custom-components","title":"IBM Langflow arbitrary code execution in custom components","severity":"high","exploited":false,"published_at":"2026-09-10T22:17:01.977+00:00","url":"https://junglewise.ai/threats/cve-2026-81211-ibm-langflow-arbitrary-code-execution-in-custom-components"},{"cve":"CVE-2026-81204","cvss":9.8,"epss":0.0086,"slug":"cve-2026-81204-ibm-langflow-oss-code-injection-in-graph-construction","title":"IBM Langflow OSS code injection in graph construction","severity":"critical","exploited":false,"published_at":"2026-09-10T22:17:01.58+00:00","url":"https://junglewise.ai/threats/cve-2026-81204-ibm-langflow-oss-code-injection-in-graph-construction"},{"cve":"CVE-2026-79742","cvss":8.8,"epss":0.0081,"slug":"cve-2026-79742-ibm-langflow-oss-arbitrary-code-execution-via-incomplete","title":"IBM Langflow OSS arbitrary code execution via incomplete environment variable blocklist","severity":"high","exploited":false,"published_at":"2026-09-10T22:17:00.78+00:00","url":"https://junglewise.ai/threats/cve-2026-79742-ibm-langflow-oss-arbitrary-code-execution-via-incomplete"},{"cve":"CVE-2026-79725","cvss":6.5,"epss":0.0042,"slug":"cve-2026-79725-ibm-langflow-oss-path-traversal-and-improper-access-control","title":"IBM Langflow OSS path traversal and improper access control","severity":"medium","exploited":false,"published_at":"2026-09-10T22:17:00.657+00:00","url":"https://junglewise.ai/threats/cve-2026-79725-ibm-langflow-oss-path-traversal-and-improper-access-control"},{"cve":"CVE-2026-79724","cvss":9.8,"epss":0.0067,"slug":"cve-2026-79724-ibm-langflow-os-command-injection-via-improper-neutralization","title":"IBM Langflow OS command injection via improper neutralization","severity":"critical","exploited":false,"published_at":"2026-09-10T22:17:00.53+00:00","url":"https://junglewise.ai/threats/cve-2026-79724-ibm-langflow-os-command-injection-via-improper-neutralization"},{"cve":"CVE-2026-79723","cvss":5,"epss":0.0035,"slug":"cve-2026-79723-ibm-langflow-oss-server-side-request-forgery-in-api-endpoint","title":"IBM Langflow OSS server-side request forgery in API endpoint validation","severity":"medium","exploited":false,"published_at":"2026-09-10T22:17:00.387+00:00","url":"https://junglewise.ai/threats/cve-2026-79723-ibm-langflow-oss-server-side-request-forgery-in-api-endpoint"},{"cve":"CVE-2026-78575","cvss":8.8,"epss":0.0079,"slug":"cve-2026-78575-ibm-langflow-oss-command-injection-in-mcp-stdio-configuration","title":"IBM Langflow OSS command injection in MCP stdio configuration","severity":"high","exploited":false,"published_at":"2026-09-10T22:17:00.13+00:00","url":"https://junglewise.ai/threats/cve-2026-78575-ibm-langflow-oss-command-injection-in-mcp-stdio-configuration"},{"cve":"CVE-2026-78571","cvss":8.8,"epss":0.0081,"slug":"cve-2026-78571-ibm-langflow-code-injection-in-eval-call","title":"IBM Langflow code injection in eval() call","severity":"high","exploited":false,"published_at":"2026-09-10T22:16:59.853+00:00","url":"https://junglewise.ai/threats/cve-2026-78571-ibm-langflow-code-injection-in-eval-call"},{"cve":"CVE-2026-78569","cvss":8.8,"epss":0.0065,"slug":"cve-2026-78569-ibm-langflow-oss-incomplete-denylist-code-execution","title":"IBM Langflow OSS incomplete denylist code execution","severity":"high","exploited":false,"published_at":"2026-09-10T22:16:59.723+00:00","url":"https://junglewise.ai/threats/cve-2026-78569-ibm-langflow-oss-incomplete-denylist-code-execution"},{"cve":"CVE-2026-76059","cvss":8.8,"epss":0.0068,"slug":"cve-2026-76059-ibm-langflow-oss-static-security-scanner-bypass-via-annotated","title":"IBM Langflow OSS static security scanner bypass via annotated class-body assignment","severity":"high","exploited":false,"published_at":"2026-09-10T22:16:59.59+00:00","url":"https://junglewise.ai/threats/cve-2026-76059-ibm-langflow-oss-static-security-scanner-bypass-via-annotated"},{"cve":"CVE-2026-9225","cvss":6.5,"epss":0.0035,"slug":"cve-2026-9225-ibm-langflow-access-control-bypass-in-file-read-component","title":"IBM Langflow access control bypass in File Read component","severity":"medium","exploited":false,"published_at":"2026-09-10T21:17:54.34+00:00","url":"https://junglewise.ai/threats/cve-2026-9225-ibm-langflow-access-control-bypass-in-file-read-component"},{"cve":"CVE-2026-85025","cvss":9.8,"epss":0.0061,"slug":"cve-2026-85025-ibm-langflow-arbitrary-code-execution-in-mcp-endpoints","title":"IBM Langflow arbitrary code execution in MCP endpoints","severity":"critical","exploited":false,"published_at":"2026-09-10T21:17:51.99+00:00","url":"https://junglewise.ai/threats/cve-2026-85025-ibm-langflow-arbitrary-code-execution-in-mcp-endpoints"},{"cve":"CVE-2026-17631","cvss":5,"epss":0.0023,"slug":"cve-2026-17631-ibm-langflow-oss-server-side-request-forgery-in-flow-components","title":"IBM Langflow OSS server-side request forgery in flow components","severity":"medium","exploited":false,"published_at":"2026-09-04T17:16:55.507+00:00","url":"https://junglewise.ai/threats/cve-2026-17631-ibm-langflow-oss-server-side-request-forgery-in-flow-components"},{"cve":"CVE-2026-17627","cvss":4.9,"epss":0.002,"slug":"cve-2026-17627-ibm-langflow-oss-authorization-bypass-in-voice-mode-websocket","title":"IBM Langflow OSS authorization bypass in voice-mode WebSocket","severity":"medium","exploited":false,"published_at":"2026-09-04T17:16:55.38+00:00","url":"https://junglewise.ai/threats/cve-2026-17627-ibm-langflow-oss-authorization-bypass-in-voice-mode-websocket"},{"cve":"CVE-2026-17622","cvss":6.5,"epss":0.0049,"slug":"cve-2026-17622-ibm-langflow-oss-path-traversal-in-file-and-knowledge-base","title":"IBM Langflow OSS path traversal in file and knowledge base components","severity":"medium","exploited":false,"published_at":"2026-09-04T17:16:55.227+00:00","url":"https://junglewise.ai/threats/cve-2026-17622-ibm-langflow-oss-path-traversal-in-file-and-knowledge-base"},{"cve":"CVE-2026-17621","cvss":5.4,"epss":0.0029,"slug":"cve-2026-17621-ibm-langflow-oss-path-traversal-in-file-and-directory-components","title":"IBM Langflow OSS path traversal in file and directory components","severity":"medium","exploited":false,"published_at":"2026-09-04T17:16:55.063+00:00","url":"https://junglewise.ai/threats/cve-2026-17621-ibm-langflow-oss-path-traversal-in-file-and-directory-components"},{"cve":"CVE-2026-14470","cvss":6.5,"epss":0.0034,"slug":"cve-2026-14470-ibm-langflow-oss-path-traversal-in-file-components","title":"IBM Langflow OSS path traversal in file components","severity":"medium","exploited":false,"published_at":"2026-09-04T17:16:51.847+00:00","url":"https://junglewise.ai/threats/cve-2026-14470-ibm-langflow-oss-path-traversal-in-file-components"},{"cve":"CVE-2026-19306","cvss":7.7,"epss":0.004,"slug":"cve-2026-19306-ibm-langflow-oss-path-traversal-in-file-upload","title":"IBM Langflow OSS path traversal in file upload","severity":"high","exploited":false,"published_at":"2026-09-04T16:17:24.793+00:00","url":"https://junglewise.ai/threats/cve-2026-19306-ibm-langflow-oss-path-traversal-in-file-upload"},{"cve":"CVE-2026-19305","cvss":8.6,"epss":0.0029,"slug":"cve-2026-19305-ibm-langflow-oss-server-side-request-forgery-in-url-validation","title":"IBM Langflow OSS server-side request forgery in URL validation","severity":"high","exploited":false,"published_at":"2026-09-04T16:17:24.323+00:00","url":"https://junglewise.ai/threats/cve-2026-19305-ibm-langflow-oss-server-side-request-forgery-in-url-validation"}],"weekly":[{"week":"2026-06-29","critical":1,"exploited":1,"vulnerabilities":2},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-08-10","critical":1,"exploited":0,"vulnerabilities":1},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-24","critical":2,"exploited":0,"vulnerabilities":8},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":17},{"week":"2026-09-07","critical":3,"exploited":0,"vulnerabilities":18},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"Langflow","slug":"langflow","vendor":{"name":"Langflow","slug":"langflow","url":"https://junglewise.ai/threats/vendors/langflow"},"aliases":[],"category":"library","homepage":"https://www.langflow.org/","repo_url":"https://github.com/langflow-ai/langflow","description":"Langflow is a low-code platform for building and deploying multi-agent AI applications and RAG workflows.","url":"https://junglewise.ai/threats/technologies/langflow"},"most_severe":[{"cve":"CVE-2026-55255","cvss":9.9,"epss":0.0089,"slug":"cve-2026-55255-langflow-idor-in-responses-endpoint-allows-cross-user-flow","title":"Langflow IDOR in responses endpoint allows cross-user flow execution","severity":"critical","exploited":true,"published_at":"2026-06-23T17:17:08.05+00:00","url":"https://junglewise.ai/threats/cve-2026-55255-langflow-idor-in-responses-endpoint-allows-cross-user-flow"},{"cve":"CVE-2026-0770","cvss":9.8,"epss":0.6384,"slug":"cve-2026-0770-langflow-remote-code-execution-in-validate-endpoint","title":"Langflow remote code execution in validate endpoint","severity":"critical","exploited":true,"published_at":"2026-01-23T04:16:04.063+00:00","url":"https://junglewise.ai/threats/cve-2026-0770-langflow-remote-code-execution-in-validate-endpoint"},{"cve":"CVE-2026-33017","cvss":9.8,"epss":0.2476,"slug":"cve-2026-33017-langflow-unauthenticated-remote-code-execution-in-build-public","title":"Langflow unauthenticated remote code execution in build_public_tmp endpoint","severity":"critical","exploited":true,"published_at":"2026-03-20T05:16:15.55+00:00","url":"https://junglewise.ai/threats/cve-2026-33017-langflow-unauthenticated-remote-code-execution-in-build-public"},{"cve":"CVE-2025-34291","cvss":8.8,"epss":0.9281,"slug":"cve-2025-34291-langflow-cors-misconfiguration-and-account-takeover-leading-to","title":"Langflow CORS misconfiguration enables Account Takeover and RCE","severity":"critical","exploited":true,"published_at":"2025-12-06T00:31:36+00:00","url":"https://junglewise.ai/threats/cve-2025-34291-langflow-cors-misconfiguration-and-account-takeover-leading-to"},{"cve":"CVE-2025-3248","cvss":4,"epss":0.9999,"slug":"cve-2025-3248-langflow-missing-authentication-vulnerability","title":"PYSEC-2026-380 - Langflow Unauth RCE","severity":"critical","exploited":true,"published_at":"2026-06-29T11:50:38.28269+00:00","url":"https://junglewise.ai/threats/cve-2025-3248-langflow-missing-authentication-vulnerability"},{"cve":"CVE-2026-19295","cvss":9.9,"epss":0.0327,"slug":"cve-2026-19295-ibm-langflow-oss-eval-injection-in-schema-creation","title":"IBM Langflow OSS eval injection in schema creation","severity":"critical","exploited":false,"published_at":"2026-08-28T22:16:47.613+00:00","url":"https://junglewise.ai/threats/cve-2026-19295-ibm-langflow-oss-eval-injection-in-schema-creation"},{"cve":"CVE-2026-33309","cvss":9.9,"epss":0.0105,"slug":"cve-2026-33309-langflow-path-traversal-and-arbitrary-file-write-in-v2-api","title":"Langflow path traversal and arbitrary file write in v2 API","severity":"critical","exploited":false,"published_at":"2026-03-19T17:46:43+00:00","url":"https://junglewise.ai/threats/cve-2026-33309-langflow-path-traversal-and-arbitrary-file-write-in-v2-api"},{"cve":"CVE-2024-42835","cvss":9.8,"epss":0.0116,"slug":"cve-2024-42835-langflow-remote-code-execution-in-pythoncodetool","title":"Langflow remote code execution in PythonCodeTool","severity":"critical","exploited":false,"published_at":"2024-10-31T15:30:59+00:00","url":"https://junglewise.ai/threats/cve-2024-42835-langflow-remote-code-execution-in-pythoncodetool"},{"cve":"CVE-2026-81204","cvss":9.8,"epss":0.0086,"slug":"cve-2026-81204-ibm-langflow-oss-code-injection-in-graph-construction","title":"IBM Langflow OSS code injection in graph construction","severity":"critical","exploited":false,"published_at":"2026-09-10T22:17:01.58+00:00","url":"https://junglewise.ai/threats/cve-2026-81204-ibm-langflow-oss-code-injection-in-graph-construction"},{"cve":"CVE-2026-19286","cvss":9.8,"epss":0.008,"slug":"cve-2026-19286-ibm-langflow-oss-remote-code-execution-in-a2a-endpoint","title":"IBM Langflow OSS remote code execution in A2A endpoint","severity":"critical","exploited":false,"published_at":"2026-08-28T22:16:47.357+00:00","url":"https://junglewise.ai/threats/cve-2026-19286-ibm-langflow-oss-remote-code-execution-in-a2a-endpoint"}],"generated_at":"2026-09-26T13:07:00.120236+00:00"}