Langflow Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Langflow products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

6

In CISA KEV

5

Beyond CISA KEV

1

Sensor Observed

4

Virtual Patch Available

1

Langflow KEVs Added by Year

Loading...

6 Langflow KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2026-0770

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability

Confirmed In CISA 21 Jul 2026
CVE-2026-55255

Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow

Confirmed In CISA 07 Jul 2026
CVE-2026-5027

Langflow - Path Traversal Arbitrary File Write via upload_user_file

Confirmed Not in CISA 10 Jun 2026
CVE-2025-34291

Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE

Confirmed In CISA 01 Jun 2026
CVE-2026-33017

Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint

Confirmed In CISA 01 Jun 2026
CVE-2025-3248

Langflow Unauth RCE

Confirmed In CISA 05 May 2025

Common Vulnerability Classes (CWE)

  • CWE-306 — Missing Authentication for Critical Function 2
  • CWE-346 — Origin Validation Error 1
  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 1
  • CWE-829 — Inclusion of Functionality from Untrusted Control Sphere 1
  • CWE-94 — Improper Control of Generation of Code ('Code Injection') 1
  • CWE-95 — Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') 1
  • CWE-639 — Authorization Bypass Through User-Controlled Key 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology