{"schema_version":1,"title":"langflow (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 32 vulnerabilities in langflow (PyPI): 0 in the last 7 days and 5 in the last 90 days, 12 of them critical and 5 exploited in the wild. The most recent, CVE-2026-21445, was published on 13 July 2026.","url":"https://junglewise.ai/threats/technologies/pypi-langflow","json_url":"https://junglewise.ai/threats/technologies/pypi-langflow.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/pypi-langflow","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":7,"all_time":32,"critical":12,"exploited":5,"last_7_days":0,"last_30_days":0,"last_90_days":5,"last_365_days":30},"latest":[{"cve":"CVE-2026-21445","cvss":4,"epss":0.3371,"slug":"cve-2026-21445-langflow-missing-authentication-on-critical-api-endpoints","title":"PYSEC-2026-2571 - Langflow Missing Authentication on Critical API Endpoints","severity":"medium","exploited":false,"published_at":"2026-07-13T14:36:34.368605+00:00","url":"https://junglewise.ai/threats/cve-2026-21445-langflow-missing-authentication-on-critical-api-endpoints"},{"cve":"CVE-2025-68477","cvss":3.1,"epss":0.063,"slug":"cve-2025-68477-langflow-vulnerable-to-server-side-request-forgery","title":"PYSEC-2026-1522 - Langflow vulnerable to Server-Side Request Forgery","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:13.87515+00:00","url":"https://junglewise.ai/threats/cve-2025-68477-langflow-vulnerable-to-server-side-request-forgery"},{"cve":"CVE-2025-57760","cvss":3.1,"epss":0.0052,"slug":"cve-2025-57760-langflow-vulnerable-to-privilege-escalation-via-cli-superuser","title":"PYSEC-2026-1526 - Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:01.786985+00:00","url":"https://junglewise.ai/threats/cve-2025-57760-langflow-vulnerable-to-privilege-escalation-via-cli-superuser"},{"cve":"CVE-2024-48061","cvss":3.1,"epss":0.0154,"slug":"cve-2024-48061-langflow-vulnerable-to-remote-code-execution","title":"PYSEC-2026-1523 - Langflow vulnerable to remote code execution","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:43.96786+00:00","url":"https://junglewise.ai/threats/cve-2024-48061-langflow-vulnerable-to-remote-code-execution"},{"cve":"CVE-2024-9277","cvss":3.1,"epss":0.0096,"slug":"cve-2024-9277-langflow-inefficient-regular-expression-complexity-in-http-post","title":"PYSEC-2026-1521 - Inefficient Regular Expression Complexity in langflow","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:42.535963+00:00","url":"https://junglewise.ai/threats/cve-2024-9277-langflow-inefficient-regular-expression-complexity-in-http-post"},{"cve":"CVE-2026-27966","cvss":3.1,"epss":0.0249,"slug":"cve-2026-27966-langflow-csv-agent-remote-code-execution-via-hardcoded-python","title":"PYSEC-2026-376 - Langflow has Remote Code Execution in CSV Agent","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:51.356749+00:00","url":"https://junglewise.ai/threats/cve-2026-27966-langflow-csv-agent-remote-code-execution-via-hardcoded-python"},{"cve":"CVE-2025-3248","cvss":4,"epss":0.9999,"slug":"cve-2025-3248-langflow-missing-authentication-vulnerability","title":"PYSEC-2026-380 - Langflow Unauth RCE","severity":"critical","exploited":true,"published_at":"2026-06-29T11:50:38.28269+00:00","url":"https://junglewise.ai/threats/cve-2025-3248-langflow-missing-authentication-vulnerability"},{"cve":"CVE-2026-55450","cvss":9.3,"epss":0.0119,"slug":"cve-2026-55450-langflow-unauthenticated-file-upload-and-path-disclosure-in","title":"Langflow unauthenticated file upload and path disclosure in upload endpoint","severity":"critical","exploited":false,"published_at":"2026-06-23T17:17:08.663+00:00","url":"https://junglewise.ai/threats/cve-2026-55450-langflow-unauthenticated-file-upload-and-path-disclosure-in"},{"cve":"CVE-2026-55447","cvss":9.6,"epss":0.0066,"slug":"cve-2026-55447-langflow-arbitrary-file-read-and-rce-via-symlink-following-in","title":"Langflow arbitrary file read and RCE via symlink following in BaseFileComponent","severity":"critical","exploited":false,"published_at":"2026-06-23T17:17:08.54+00:00","url":"https://junglewise.ai/threats/cve-2026-55447-langflow-arbitrary-file-read-and-rce-via-symlink-following-in"},{"cve":"CVE-2026-55446","cvss":7.5,"epss":0.0058,"slug":"cve-2026-55446-langflow-unauthenticated-denial-of-service-in-file-upload","title":"Langflow unauthenticated denial of service in file upload","severity":"high","exploited":false,"published_at":"2026-06-23T17:17:08.41+00:00","url":"https://junglewise.ai/threats/cve-2026-55446-langflow-unauthenticated-denial-of-service-in-file-upload"},{"cve":"CVE-2026-55423","cvss":6.1,"epss":0.0022,"slug":"cve-2026-55423-langflow-insufficient-session-expiration-in-logout-mechanism","title":"Langflow insufficient session expiration in logout mechanism","severity":"medium","exploited":false,"published_at":"2026-06-23T17:17:08.283+00:00","url":"https://junglewise.ai/threats/cve-2026-55423-langflow-insufficient-session-expiration-in-logout-mechanism"},{"cve":"CVE-2026-55255","cvss":9.9,"epss":0.0089,"slug":"cve-2026-55255-langflow-idor-in-responses-endpoint-allows-cross-user-flow","title":"Langflow IDOR in responses endpoint allows cross-user flow execution","severity":"critical","exploited":true,"published_at":"2026-06-23T17:17:08.05+00:00","url":"https://junglewise.ai/threats/cve-2026-55255-langflow-idor-in-responses-endpoint-allows-cross-user-flow"},{"cve":"CVE-2026-48520","cvss":6.1,"epss":0.0044,"slug":"cve-2026-48520-langflow-arbitrary-file-read-in-shareable-playground","title":"Langflow arbitrary file read in Shareable Playground","severity":"medium","exploited":false,"published_at":"2026-06-23T17:17:01.367+00:00","url":"https://junglewise.ai/threats/cve-2026-48520-langflow-arbitrary-file-read-in-shareable-playground"},{"cve":"CVE-2026-48519","cvss":9.6,"epss":0.0078,"slug":"cve-2026-48519-langflow-rce-in-shareable-playground-via-public-flows-api","title":"Langflow RCE in Shareable Playground via Public Flows API","severity":"critical","exploited":false,"published_at":"2026-06-23T17:17:01.24+00:00","url":"https://junglewise.ai/threats/cve-2026-48519-langflow-rce-in-shareable-playground-via-public-flows-api"},{"cve":"CVE-2026-42867","cvss":6.5,"epss":0.0047,"slug":"cve-2026-42867-langflow-path-traversal-in-knowledge-bases-api","title":"Langflow path traversal in Knowledge Bases API","severity":"medium","exploited":false,"published_at":"2026-06-23T17:16:58.857+00:00","url":"https://junglewise.ai/threats/cve-2026-42867-langflow-path-traversal-in-knowledge-bases-api"},{"cve":"CVE-2026-33760","cvss":8.8,"epss":0.005,"slug":"cve-2026-33760-langflow-idor-in-monitor-api-endpoints","title":"Langflow IDOR in monitor API endpoints","severity":"high","exploited":false,"published_at":"2026-06-23T17:16:52.79+00:00","url":"https://junglewise.ai/threats/cve-2026-33760-langflow-idor-in-monitor-api-endpoints"},{"cve":"CVE-2026-42048","cvss":9.6,"epss":0.006,"slug":"cve-2026-42048-langflow-path-traversal-in-knowledge-bases-api-bulk-delete","title":"Langflow path traversal in Knowledge Bases API bulk delete","severity":"critical","exploited":false,"published_at":"2026-05-12T18:17:23.78+00:00","url":"https://junglewise.ai/threats/cve-2026-42048-langflow-path-traversal-in-knowledge-bases-api-bulk-delete"},{"cve":"CVE-2026-6598","cvss":4.3,"epss":0.0024,"slug":"cve-2026-6598-langflow-cleartext-storage-of-authentication-settings-in-project","title":"Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint","severity":"medium","exploited":false,"published_at":"2026-04-20T06:31:27+00:00","url":"https://junglewise.ai/threats/cve-2026-6598-langflow-cleartext-storage-of-authentication-settings-in-project"},{"cve":"CVE-2026-6599","cvss":6.3,"epss":0.0039,"slug":"cve-2026-6599-langflow-vulnerable-to-injection","title":"Langflow vulnerable to injection","severity":"medium","exploited":false,"published_at":"2026-04-20T06:31:27+00:00","url":"https://junglewise.ai/threats/cve-2026-6599-langflow-vulnerable-to-injection"},{"cve":"CVE-2026-6597","cvss":3.1,"epss":0.0038,"slug":"cve-2026-6597-langflow-has-an-information-leak-through-incomplete-api-key","title":"Langflow has an Information Leak through Incomplete API Key Redaction","severity":"low","exploited":false,"published_at":"2026-04-20T03:34:42+00:00","url":"https://junglewise.ai/threats/cve-2026-6597-langflow-has-an-information-leak-through-incomplete-api-key"},{"cve":"CVE-2026-34046","cvss":8.8,"epss":0.0068,"slug":"cve-2026-34046-langflow-authorization-bypass-in-flow-management-api","title":"Langflow authorization bypass in flow management API","severity":"high","exploited":false,"published_at":"2026-03-27T21:17:27.753+00:00","url":"https://junglewise.ai/threats/cve-2026-34046-langflow-authorization-bypass-in-flow-management-api"},{"cve":"CVE-2026-33873","cvss":4,"epss":0.0182,"slug":"cve-2026-33873-langflow-authenticated-code-execution-in-agentic-assistant","title":"Langflow authenticated code execution in Agentic Assistant validation","severity":"critical","exploited":false,"published_at":"2026-03-26T18:31:36+00:00","url":"https://junglewise.ai/threats/cve-2026-33873-langflow-authenticated-code-execution-in-agentic-assistant"},{"cve":"CVE-2026-33497","cvss":4,"epss":0.0203,"slug":"cve-2026-33497-langflow-path-traversal-in-profile-picture-endpoint","title":"Langflow path traversal in profile picture endpoint","severity":"high","exploited":false,"published_at":"2026-03-20T20:56:14+00:00","url":"https://junglewise.ai/threats/cve-2026-33497-langflow-path-traversal-in-profile-picture-endpoint"},{"cve":"CVE-2026-33484","cvss":7.5,"epss":0.0056,"slug":"cve-2026-33484-langflow-unauthenticated-idor-in-image-download-endpoint","title":"Langflow unauthenticated IDOR in image download endpoint","severity":"high","exploited":false,"published_at":"2026-03-20T20:47:10+00:00","url":"https://junglewise.ai/threats/cve-2026-33484-langflow-unauthenticated-idor-in-image-download-endpoint"},{"cve":"CVE-2026-33017","cvss":9.8,"epss":0.2476,"slug":"cve-2026-33017-langflow-unauthenticated-remote-code-execution-in-build-public","title":"Langflow unauthenticated remote code execution in build_public_tmp endpoint","severity":"critical","exploited":true,"published_at":"2026-03-20T05:16:15.55+00:00","url":"https://junglewise.ai/threats/cve-2026-33017-langflow-unauthenticated-remote-code-execution-in-build-public"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"langflow (PyPI)","slug":"pypi-langflow","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"description":"Python framework for building visual AI applications with component-based workflows.","url":"https://junglewise.ai/threats/technologies/pypi-langflow"},"most_severe":[{"cve":"CVE-2026-55255","cvss":9.9,"epss":0.0089,"slug":"cve-2026-55255-langflow-idor-in-responses-endpoint-allows-cross-user-flow","title":"Langflow IDOR in responses endpoint allows cross-user flow execution","severity":"critical","exploited":true,"published_at":"2026-06-23T17:17:08.05+00:00","url":"https://junglewise.ai/threats/cve-2026-55255-langflow-idor-in-responses-endpoint-allows-cross-user-flow"},{"cve":"CVE-2026-0770","cvss":9.8,"epss":0.6384,"slug":"cve-2026-0770-langflow-remote-code-execution-in-validate-endpoint","title":"Langflow remote code execution in validate endpoint","severity":"critical","exploited":true,"published_at":"2026-01-23T04:16:04.063+00:00","url":"https://junglewise.ai/threats/cve-2026-0770-langflow-remote-code-execution-in-validate-endpoint"},{"cve":"CVE-2026-33017","cvss":9.8,"epss":0.2476,"slug":"cve-2026-33017-langflow-unauthenticated-remote-code-execution-in-build-public","title":"Langflow unauthenticated remote code execution in build_public_tmp endpoint","severity":"critical","exploited":true,"published_at":"2026-03-20T05:16:15.55+00:00","url":"https://junglewise.ai/threats/cve-2026-33017-langflow-unauthenticated-remote-code-execution-in-build-public"},{"cve":"CVE-2025-34291","cvss":8.8,"epss":0.9281,"slug":"cve-2025-34291-langflow-cors-misconfiguration-and-account-takeover-leading-to","title":"Langflow CORS misconfiguration enables Account Takeover and RCE","severity":"critical","exploited":true,"published_at":"2025-12-06T00:31:36+00:00","url":"https://junglewise.ai/threats/cve-2025-34291-langflow-cors-misconfiguration-and-account-takeover-leading-to"},{"cve":"CVE-2025-3248","cvss":4,"epss":0.9999,"slug":"cve-2025-3248-langflow-missing-authentication-vulnerability","title":"PYSEC-2026-380 - Langflow Unauth RCE","severity":"critical","exploited":true,"published_at":"2026-06-29T11:50:38.28269+00:00","url":"https://junglewise.ai/threats/cve-2025-3248-langflow-missing-authentication-vulnerability"},{"cve":"CVE-2026-33309","cvss":9.9,"epss":0.0105,"slug":"cve-2026-33309-langflow-path-traversal-and-arbitrary-file-write-in-v2-api","title":"Langflow path traversal and arbitrary file write in v2 API","severity":"critical","exploited":false,"published_at":"2026-03-19T17:46:43+00:00","url":"https://junglewise.ai/threats/cve-2026-33309-langflow-path-traversal-and-arbitrary-file-write-in-v2-api"},{"cve":"CVE-2024-42835","cvss":9.8,"epss":0.0116,"slug":"cve-2024-42835-langflow-remote-code-execution-in-pythoncodetool","title":"Langflow remote code execution in PythonCodeTool","severity":"critical","exploited":false,"published_at":"2024-10-31T15:30:59+00:00","url":"https://junglewise.ai/threats/cve-2024-42835-langflow-remote-code-execution-in-pythoncodetool"},{"cve":"CVE-2026-48519","cvss":9.6,"epss":0.0078,"slug":"cve-2026-48519-langflow-rce-in-shareable-playground-via-public-flows-api","title":"Langflow RCE in Shareable Playground via Public Flows API","severity":"critical","exploited":false,"published_at":"2026-06-23T17:17:01.24+00:00","url":"https://junglewise.ai/threats/cve-2026-48519-langflow-rce-in-shareable-playground-via-public-flows-api"},{"cve":"CVE-2026-55447","cvss":9.6,"epss":0.0066,"slug":"cve-2026-55447-langflow-arbitrary-file-read-and-rce-via-symlink-following-in","title":"Langflow arbitrary file read and RCE via symlink following in BaseFileComponent","severity":"critical","exploited":false,"published_at":"2026-06-23T17:17:08.54+00:00","url":"https://junglewise.ai/threats/cve-2026-55447-langflow-arbitrary-file-read-and-rce-via-symlink-following-in"},{"cve":"CVE-2026-42048","cvss":9.6,"epss":0.006,"slug":"cve-2026-42048-langflow-path-traversal-in-knowledge-bases-api-bulk-delete","title":"Langflow path traversal in Knowledge Bases API bulk delete","severity":"critical","exploited":false,"published_at":"2026-05-12T18:17:23.78+00:00","url":"https://junglewise.ai/threats/cve-2026-42048-langflow-path-traversal-in-knowledge-bases-api-bulk-delete"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}