Vulnerabilities in langflow-ai

36 results
Vexday analysis

Langflow-AI acumula 36 vulnerabilidades com 13 publicadas nos últimos 90 dias, indicando exposição contínua e recente. Duas vulnerabilidades estão sob ataque ativo em exploração real, enquanto dez atingem nível crítico (CVSS 10), com predominância de injeção de código (CWE-94) — uma categoria de alto impacto em contextos de execução remota. A velocidade de disclosure e a presença de exploits documentados demandam priorização imediata na atualização de dependências.

CVE-2026-48520MEDIUMLangflow: Unauthenticated Shareable Playground arbitrary local or S3 file readEPSS 0.4%CVE-2026-33053MEDIUMLangflow has Missing Ownership Verification in API Key Deletion (IDOR)EPSS 0.4%CVE-2026-33760HIGHLangflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 EndpointsEPSS 0.4%CVE-2026-42867MEDIUMLangflow: Path Traversal in Knowledge Bases API via Creation EndpointEPSS 0.3%CVE-2026-55446HIGHLangflow: Unauthenticated DoS through multipart form boundary file uploadEPSS 0.3%CVE-2026-6597MEDIUMlangflow-ai langflow Flow Using API core.py has_api_terms credentials storageEPSS 0.3%CVE-2026-7700MEDIUMlangflow-ai langflow LambdaFilterComponent lambda_filter.p eval code injectionEPSS 0.3%CVE-2026-6596MEDIUMlangflow-ai langflow API Endpoint endpoints.py create_upload_file unrestricted uploadEPSS 0.3%CVE-2026-5025MEDIUMLangflow - Application Logs Exposed to All Authenticated UsersEPSS 0.2%CVE-2026-12822MEDIUMlangflow-ai langflow Bundle URL Loader code injectionEPSS 0.2%CVE-2026-6599MEDIUMlangflow-ai langflow Model Context Protocol Configuration API mcp_projects.py install_mcp_config injectionEPSS 0.2%CVE-2026-5022MEDIUMLangflow - Missing Authorization on download_image EndpointEPSS 0.2%CVE-2026-6600MEDIUMlangflow-ai langflow Frontend React Component Rendering edit-message.tsx cross site scriptingEPSS 0.2%CVE-2026-55423MEDIUMLangflow: Logout button does not clear sessionEPSS 0.2%CVE-2026-5026HIGHLangflow - Stored XSS via Malicious SVG UploadEPSS 0.2%CVE-2026-6598MEDIUMlangflow-ai langflow Project Creation Endpoint projects.py encrypt_auth_settings cleartext storage in fileEPSS 0.2%