Vendor
Langflow vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 64 vulnerabilities in Langflow: 0 in the last 7 days and 48 in the last 90 days, 14 of them critical and 5 exploited in the wild. The most recent, CVE-2026-84889, was published on 10 September 2026. 1 technology has a page of its own.
- Last 7 days
- 0
- Last 90 days
- 48
- Critical, all time
- 14
- Exploited in the wild
- 5
About Langflow
Langflow is a provider of low-code visual development tools for building multi-agent AI applications.
Langflow technologies
- Langflow76
Latest Langflow vulnerabilities
- CVE-2026-84889: IBM Langflow OSS path traversal arbitrary file writehighCVSS 8.8EPSS 0.9%
- CVE-2026-81941: IBM Langflow OSS privilege escalation in MCP Tools componenthighCVSS 8.8EPSS 0.6%
- CVE-2026-81940: IBM Langflow OSS code injection in flow display nameshighCVSS 8.8EPSS 0.8%
- CVE-2026-81268: IBM Langflow OSS insufficient API key session expirationhighCVSS 8.1EPSS 0.4%
- CVE-2026-81265: IBM Langflow OSS server-side request forgery via URL validation bypasshighCVSS 7.5EPSS 0.4%
- CVE-2026-81213: IBM Langflow server-side request forgery in URL validationhighCVSS 8.6EPSS 0.5%
- CVE-2026-81211: IBM Langflow arbitrary code execution in custom componentshighCVSS 8.8EPSS 0.5%
- CVE-2026-81204: IBM Langflow OSS code injection in graph constructioncriticalCVSS 9.8EPSS 0.9%
- CVE-2026-79742: IBM Langflow OSS arbitrary code execution via incomplete environment variable blocklisthighCVSS 8.8EPSS 0.8%
- CVE-2026-79725: IBM Langflow OSS path traversal and improper access controlmediumCVSS 6.5EPSS 0.4%
- CVE-2026-79724: IBM Langflow OS command injection via improper neutralizationcriticalCVSS 9.8EPSS 0.7%
- CVE-2026-79723: IBM Langflow OSS server-side request forgery in API endpoint validationmediumCVSS 5EPSS 0.4%
- CVE-2026-78575: IBM Langflow OSS command injection in MCP stdio configurationhighCVSS 8.8EPSS 0.8%
- CVE-2026-78571: IBM Langflow code injection in eval() callhighCVSS 8.8EPSS 0.8%
- CVE-2026-78569: IBM Langflow OSS incomplete denylist code executionhighCVSS 8.8EPSS 0.7%
- CVE-2026-76059: IBM Langflow OSS static security scanner bypass via annotated class-body assignmenthighCVSS 8.8EPSS 0.7%
- CVE-2026-9225: IBM Langflow access control bypass in File Read componentmediumCVSS 6.5EPSS 0.4%
- CVE-2026-85025: IBM Langflow arbitrary code execution in MCP endpointscriticalCVSS 9.8EPSS 0.6%
- CVE-2026-17631: IBM Langflow OSS server-side request forgery in flow componentsmediumCVSS 5EPSS 0.2%
- CVE-2026-17627: IBM Langflow OSS authorization bypass in voice-mode WebSocketmediumCVSS 4.9EPSS 0.2%
- CVE-2026-17622: IBM Langflow OSS path traversal in file and knowledge base componentsmediumCVSS 6.5EPSS 0.5%
- CVE-2026-17621: IBM Langflow OSS path traversal in file and directory componentsmediumCVSS 5.4EPSS 0.3%
- CVE-2026-14470: IBM Langflow OSS path traversal in file componentsmediumCVSS 6.5EPSS 0.3%
- CVE-2026-19306: IBM Langflow OSS path traversal in file uploadhighCVSS 7.7EPSS 0.4%
- CVE-2026-19305: IBM Langflow OSS server-side request forgery in URL validationhighCVSS 8.6EPSS 0.3%
Most severe Langflow vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-55255: Langflow IDOR in responses endpoint allows cross-user flow executioncriticalexploited in the wildCVSS 9.9EPSS 0.9%
- CVE-2026-0770: Langflow remote code execution in validate endpointcriticalexploited in the wildCVSS 9.8EPSS 63.8%
- CVE-2026-33017: Langflow unauthenticated remote code execution in build_public_tmp endpointcriticalexploited in the wildCVSS 9.8EPSS 24.8%
- CVE-2025-34291: Langflow CORS misconfiguration enables Account Takeover and RCEcriticalexploited in the wildCVSS 8.8EPSS 92.8%
- CVE-2025-3248: Langflow Unauth RCEcriticalexploited in the wildCVSS 4EPSS 100.0%
- CVE-2026-19295: IBM Langflow OSS eval injection in schema creationcriticalCVSS 9.9EPSS 3.3%
- CVE-2026-33309: Langflow path traversal and arbitrary file write in v2 APIcriticalCVSS 9.9EPSS 1.1%
- CVE-2026-81204: IBM Langflow OSS code injection in graph constructioncriticalCVSS 9.8EPSS 0.9%
- CVE-2026-19286: IBM Langflow OSS remote code execution in A2A endpointcriticalCVSS 9.8EPSS 0.8%
- CVE-2026-79724: IBM Langflow OS command injection via improper neutralizationcriticalCVSS 9.8EPSS 0.7%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 3 | 0 | |
| 10 Aug 2026 | 1 | 1 | |
| 17 Aug 2026 | 1 | 0 | |
| 24 Aug 2026 | 8 | 2 | |
| 31 Aug 2026 | 17 | 0 | |
| 7 Sep 2026 | 18 | 3 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/langflow.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Langflow vulnerabilities", https://junglewise.ai/threats/vendors/langflow, 26 September 2026.