Security: langflow-ai/langflow
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Authenticated Code Execution in Agentic Assistant ValidationGHSA-v8hw-mh8c-jxfc published
Mar 24, 2026 by andifilhohubCritical -
Unauthenticated Remote Code Execution in Langflow via Public Flow Build EndpointGHSA-vwmf-pq79-vjvx published
Mar 16, 2026 by andifilhohubCritical -
Unauthenticated IDOR on Image DownloadsGHSA-7grx-3xcx-2xv5 published
Mar 20, 2026 by andifilhohubHigh -
Arbitrary File Write (RCE) via v2 APIGHSA-g2j9-7rj2-gm6c published
Mar 18, 2026 by andifilhohubCritical -
Missing Ownership Verification in API Key Deletion (IDOR)GHSA-rf6x-r45m-xv3w published
Mar 16, 2026 by andifilhohubHigh -
Remote Code Execution in CSV AgentGHSA-3645-fxcv-hqr4 published
Feb 25, 2026 by EmpreiteiroCritical -
SSRF in langflow-ai/langflowGHSA-5993-7p27-66g5 published
Dec 19, 2025 by jordanrfrazierHigh -
External Control of File Name or Path in LangflowGHSA-f43r-cc68-gpx4 published
Dec 19, 2025 by jordanrfrazierHigh -
Missing Authentication on Critical API EndpointsGHSA-c5cp-vx83-jhqx published
Jan 2, 2026 by jordanrfrazierCritical -
Privilege Escalation via CLI Superuser Creation (Post-RCE)GHSA-4gv9-mp8m-592r published
Aug 25, 2025 by jordanrfrazierHigh