PyPI package intelligence
langflow Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting the PyPI package langflow, including the gap beyond CISA KEV, confidence assessments, and sensor observations.
- Total KEVs
- 8
- Known exploited vulnerabilities affecting langflow
- In CISA KEV
- 5
- Records also listed in the official catalog
- Beyond CISA KEV
- 3
- Additional exploited vulnerabilities absent from CISA KEV
- Sensor Observed
- 6
- langflow KEVs with sensor-observed exploitation activity
Review langflow exploitation against the versions you run
Three of the eight exploited langflow vulnerabilities tracked here are not in CISA KEV.
- 63%
- Covered by CISA
- 37%
- Beyond CISA
Attested langflow vulnerabilities
8 known exploited vulnerabilities affecting this package.
| Vulnerability | CISA KEV | Added |
|---|---|---|
|
CVE-2026-33497
Langflow: /profile_pictures/{folder_name}/{file_name} endpoint file reading |
Beyond CISA | 11 Aug 2026 |
|
CVE-2026-55450
Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak |
Beyond CISA | 09 Aug 2026 |
|
CVE-2024-37014
Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and provide... |
Beyond CISA | 01 Aug 2026 |
|
CVE-2026-0770
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability |
In CISA | 21 Jul 2026 |
|
CVE-2026-55255
Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow |
In CISA | 07 Jul 2026 |
|
CVE-2025-34291
Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE |
In CISA | 01 Jun 2026 |
|
CVE-2026-33017
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint |
In CISA | 01 Jun 2026 |
|
CVE-2025-3248
Langflow Unauth RCE |
In CISA | 05 May 2025 |
Recurring weakness patterns
Missing Authentication for Critical Function, Improper Control of Generation of Code ('Code Injection'), and Origin Validation Error account for mapped occurrences across this langflow KEV portfolio.
CWE-306
Missing Authentication for Critical Function
CWE-94
Improper Control of Generation of Code ('Code Injection')
CWE-346
Origin Validation Error
CWE-400
Uncontrolled Resource Consumption
CWE-639
Authorization Bypass Through User-Controlled Key
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CWE-95
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')