CVE-2024-37014

Confirmed PUBLISHED

Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and provide...

Vendor: langflow-ai Product: Langflow

Not yet in CISA KEV

Exploited in the wild Active exploitation observed

Recommended Action

Prioritize immediate patching and validate internet-facing exposure. Monitor for matching exploitation attempts in your environment.

Confidence
Confirmed
Exploitation Status
Active exploitation observed
Observed in Sensors
Yes
Attempts (30d)
185
Unique Attacker IPs
5
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
9.8 Critical EPSS 31.1%

At a Glance

Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and provide a Python script.

python
CVE Published
Jun 10, 2024
Exploitation Reported
Jul 13, 2026
CVSS
9.8 Critical
EPSS
31.1%
Remote Low complexity No user interaction Unauthenticated

Sensor telemetry available

Affected Versions

Vendor Product Version Status
langflow
langflow

0 to <= 0.6.19

Affected
n/a
n/a

n/a

Affected

CVE References