Langflow vendor intelligence

Langflow Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting Langflow products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Total KEVs
9
Known exploited vulnerabilities affecting Langflow products
In CISA KEV
5
Records also listed in the official catalog
Beyond CISA KEV
4
Additional exploited CVEs absent from CISA KEV
Sensor Observed
7
Langflow KEVs with sensor-observed exploitation activity

The catalog gap matters for Langflow exposure

Four of the nine exploited Langflow CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 44% of this vendor portfolio.

56%
Covered by CISA
44%
Beyond CISA
2
Product families

Attested Langflow CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2026-33497

Langflow: /profile_pictures/{folder_name}/{file_name} endpoint file reading

langflow Confirmed Beyond CISA 11 Aug 2026
CVE-2026-55450

Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak

langflow Confirmed Beyond CISA 09 Aug 2026
CVE-2024-37014

Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and provide...

Langflow Confirmed Beyond CISA 01 Aug 2026
CVE-2026-0770

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability

Langflow Confirmed In CISA 21 Jul 2026
CVE-2026-55255

Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow

langflow Confirmed In CISA 07 Jul 2026
CVE-2026-5027

Langflow - Path Traversal Arbitrary File Write via upload_user_file

langflow Confirmed Beyond CISA 10 Jun 2026
CVE-2025-34291

Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE

Langflow Confirmed In CISA 01 Jun 2026
CVE-2026-33017

Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint

langflow Confirmed In CISA 01 Jun 2026
CVE-2025-3248

Langflow Unauth RCE

langflow Confirmed In CISA 05 May 2025

Showing 9 of 9 Langflow known exploited vulnerabilities.

Recurring weakness patterns

Missing authentication for critical function, control, and limitation account for seven mapped occurrences across this Langflow KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.