Langflow-ai vendor intelligence

Langflow-ai Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting Langflow-ai products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse KEV feed
Total KEVs
8
Known exploited vulnerabilities affecting Langflow-ai products
In CISA KEV
3
Records also listed in the official catalog
Beyond CISA KEV
5
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
7
Langflow-ai KEVs with sensor-observed exploitation activity

The catalog gap matters for Langflow-ai exposure

Five of the eight exploited Langflow-ai vulnerabilities tracked by Previdian are not in CISA KEV. Teams relying on the official catalog alone would miss 62% of this vendor portfolio.

38%
Covered by CISA
62%
Beyond CISA
2
Product families

Attested Langflow-ai vulnerabilities

8 known exploited vulnerabilities in this exploited-vulnerability portfolio. Search, then narrow it to official CISA coverage or the additional records Previdian tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2026-51886

langflow-ai langflow v1.9.3 is affected by: Code Injection. The impact is: execute arbitrary code (remote). The component is:...

langflow Confirmed Beyond CISA 06 Oct 2026
CVE-2026-33497

Langflow: /profile_pictures/{folder_name}/{file_name} endpoint file reading

langflow Confirmed Beyond CISA 11 Aug 2026
CVE-2026-55450

Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak

langflow Confirmed Beyond CISA 09 Aug 2026
CVE-2024-37014

Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and provide...

Langflow Confirmed Beyond CISA 01 Aug 2026
CVE-2026-55255

Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow

langflow Confirmed In CISA 07 Jul 2026
CVE-2026-5027

Langflow - Path Traversal Arbitrary File Write via upload_user_file

langflow Confirmed Beyond CISA 10 Jun 2026
CVE-2026-33017

Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint

langflow Confirmed In CISA 01 Jun 2026
CVE-2025-3248

Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code

langflow Confirmed In CISA 05 May 2025

Showing 8 of 8 on this page (8 Langflow-ai known exploited vulnerabilities).

Recurring weakness patterns

Missing authentication for critical function, control, and limitation account for eight mapped occurrences across this Langflow-ai KEV portfolio.

Browse all KEVs →