Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-19875 |
|
Vulnerability in langflow (CVE-2026-19875)
vulnerability in langflow (CVE-2026-19875). Data can be tampered with by attackers.
|
| CVE-2026-19297 |
|
Vulnerability in langflow (CVE-2026-19297)
vulnerability in langflow (CVE-2026-19297). Confidential information can be exposed externally.
|
| CVE-2026-9205 |
|
Vulnerability in langflow (CVE-2026-9205)
vulnerability in langflow (CVE-2026-9205). Confidential information can be exposed externally.
|
| CVE-2026-9201 |
|
Vulnerability in langflow (CVE-2026-9201)
vulnerability in langflow (CVE-2026-9201). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9196 |
|
Code Injection in langflow (CVE-2026-9196)
code injection in langflow (CVE-2026-9196). Confidential information can be exposed externally.
|
| CVE-2026-9130 |
|
Vulnerability in langflow (CVE-2026-9130)
vulnerability in langflow (CVE-2026-9130). Confidential information can be exposed externally.
|
| CVE-2026-8478 |
|
Code Injection in langflow (CVE-2026-8478)
code injection in langflow (CVE-2026-8478). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8470 |
|
Vulnerability in langflow (CVE-2026-8470)
vulnerability in langflow (CVE-2026-8470). Data can be tampered with by attackers.
|
| CVE-2026-8182 |
|
Code Injection in langflow (CVE-2026-8182)
code injection in langflow (CVE-2026-8182). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7658 |
|
Path Traversal in path-traversal (CVE-2026-7658)
path traversal in path-traversal (CVE-2026-7658). Data can be tampered with by attackers.
|
| CVE-2026-7869 |
|
Path Traversal in path-traversal (CVE-2026-7869)
path traversal in path-traversal (CVE-2026-7869). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/knowledge_bases`.
|
| CVE-2026-8183 |
|
Path Traversal in langflow (CVE-2026-8183)
path traversal in langflow (CVE-2026-8183). Confidential information can be exposed externally.
|
| CVE-2026-17633 |
|
Code Injection in langflow (CVE-2026-17633)
code injection in langflow (CVE-2026-17633). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17632 |
|
Code Injection in langflow (CVE-2026-17632)
code injection in langflow (CVE-2026-17632). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17624 |
|
Code Injection in langflow (CVE-2026-17624)
code injection in langflow (CVE-2026-17624). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10547 |
|
Vulnerability in dos (CVE-2026-10547)
vulnerability in dos (CVE-2026-10547). Data can be tampered with by attackers. Exploitable via `POST /api/v1/build/{flow_id}/vertices`.
|
| CVE-2026-7657 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-7657)
SSRF in ssrf (CVE-2026-7657). Confidential information can be exposed externally.
|
| CVE-2026-9081 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-9081)
SSRF in ssrf (CVE-2026-9081). Confidential information can be exposed externally.
|
| CVE-2026-7646 |
|
Path Traversal in path-traversal (CVE-2026-7646)
path traversal in path-traversal (CVE-2026-7646). Confidential information can be exposed externally.
|
| CVE-2026-9077 |
|
Vulnerability in langflow (CVE-2026-9077)
vulnerability in langflow (CVE-2026-9077). Data can be tampered with by attackers.
|
| CVE-2026-10128 |
|
Information Disclosure in c (CVE-2026-10128)
vulnerability in c (CVE-2026-10128). Confidential information can be exposed externally.
|
| CVE-2026-17625 |
|
OS Command Injection in langflow (CVE-2026-17625)
OS command injection in langflow (CVE-2026-17625). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17630 |
|
Vulnerability in langflow (CVE-2026-17630)
vulnerability in langflow (CVE-2026-17630). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17626 |
|
Vulnerability in langflow (CVE-2026-17626)
vulnerability in langflow (CVE-2026-17626). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17623 |
|
OS Command Injection in langflow (CVE-2026-17623)
OS command injection in langflow (CVE-2026-17623). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8446 |
|
Vulnerability in langflow (CVE-2026-8446)
vulnerability in langflow (CVE-2026-8446). Confidential information can be exposed externally.
|
| CVE-2026-12946 |
|
Code Injection in langflow (CVE-2026-12946)
code injection in langflow (CVE-2026-12946). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10700 |
|
Vulnerability in langflow (CVE-2026-10700)
vulnerability in langflow (CVE-2026-10700). Confidential information can be exposed externally.
|
| CVE-2026-12942 |
|
Path Traversal in langflow (CVE-2026-12942)
path traversal in langflow (CVE-2026-12942). Confidential information can be exposed externally.
|
| CVE-2026-13435 |
|
Code Injection in langflow (CVE-2026-13435)
code injection in langflow (CVE-2026-13435). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13444 |
|
Vulnerability in langflow (CVE-2026-13444)
vulnerability in langflow (CVE-2026-13444). Confidential information can be exposed externally.
|
| CVE-2026-12945 |
|
Vulnerability in langflow (CVE-2026-12945)
vulnerability in langflow (CVE-2026-12945). Confidential information can be exposed externally.
|
| CVE-2026-12940 |
|
OS Command Injection in langflow (CVE-2026-12940)
OS command injection in langflow (CVE-2026-12940). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13442 |
|
Vulnerability in langflow (CVE-2026-13442)
vulnerability in langflow (CVE-2026-13442). Confidential information can be exposed externally.
|
| CVE-2026-0770 KEV |
|
[KEV] Vulnerability in langflow (CVE-2026-0770)
vulnerability in langflow (CVE-2026-0770). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-13446 |
|
Vulnerability in langflow (CVE-2026-13446)
vulnerability in langflow (CVE-2026-13446). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13445 |
|
Vulnerability in langflow (CVE-2026-13445)
vulnerability in langflow (CVE-2026-13445). Confidential information can be exposed externally.
|
| CVE-2026-8859 |
|
Path Traversal in path-traversal (CVE-2026-8859)
path traversal in path-traversal (CVE-2026-8859). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8635 |
|
Code Injection in c (CVE-2026-8635)
code injection in c (CVE-2026-8635). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8505 |
|
Vulnerability in langflow (CVE-2026-8505)
vulnerability in langflow (CVE-2026-8505). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7755 |
|
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to...
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to...
|
| CVE-2026-8481 |
|
Code Injection in c (CVE-2026-8481)
code injection in c (CVE-2026-8481). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/validate/code`.
|
| CVE-2026-8476 |
|
Unsafe Deserialization in langflow (CVE-2026-8476)
vulnerability in langflow (CVE-2026-8476). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8056 |
|
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters...
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters...
|
| CVE-2026-7872 |
|
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files...
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files...
|
| CVE-2026-7754 |
|
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery ...
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery ...
|
| CVE-2026-7667 |
|
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow...
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow...
|
| CVE-2026-14499 |
|
OS Command Injection in langflow (CVE-2026-14499)
OS command injection in langflow (CVE-2026-14499). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13448 |
|
Vulnerability in langflow (CVE-2026-13448)
vulnerability in langflow (CVE-2026-13448). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9135 |
|
Code Injection in langflow (CVE-2026-9135)
code injection in langflow (CVE-2026-9135). Successful exploitation can lead to full system takeover.
|