Langflow vendor intelligence

Langflow Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting Langflow products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

8
Total KEVs

Known exploited vulnerabilities affecting Langflow products

5
In CISA KEV

Records also listed in the official catalog

3
Beyond CISA KEV

Additional exploited CVEs absent from CISA KEV

6
Sensor Observed

Langflow KEVs with sensor-observed exploitation activity

The catalog gap matters for Langflow exposure

Three of the eight exploited Langflow CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 37% of this vendor portfolio.

63%
Covered by CISA
37%
Beyond CISA
2
Product families

Attested Langflow CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2026-55450

Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak

langflow Confirmed Beyond CISA 09 Aug 2026
CVE-2024-37014

Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and provide...

Langflow Confirmed Beyond CISA 01 Aug 2026
CVE-2026-0770

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability

Langflow Confirmed In CISA 21 Jul 2026
CVE-2026-55255

Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow

langflow Confirmed In CISA 07 Jul 2026
CVE-2026-5027

Langflow - Path Traversal Arbitrary File Write via upload_user_file

langflow Confirmed Beyond CISA 10 Jun 2026
CVE-2025-34291

Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE

Langflow Confirmed In CISA 01 Jun 2026
CVE-2026-33017

Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint

langflow Confirmed In CISA 01 Jun 2026
CVE-2025-3248

Langflow Unauth RCE

langflow Confirmed In CISA 05 May 2025

Showing 8 of 8 Langflow known exploited vulnerabilities.

Recurring weakness patterns

Missing authentication for critical function, control, and origin validation error account for six mapped occurrences across this Langflow KEV portfolio.

Browse all KEVs →

Email Alerts

Get High-Impact KEV Alerts by Email

KEV Intelligence tracks known exploited vulnerabilities beyond CISA KEV. Subscribe for occasional, curator-picked alerts when exploitation warrants attention. For every update, use the RSS feed or API.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.