langflow-ai vendor intelligence
langflow-ai Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting langflow-ai products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 7
- Known exploited vulnerabilities affecting langflow-ai products
- In CISA KEV
- 3
- Records also listed in the official catalog
- Beyond CISA KEV
- 4
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 6
- langflow-ai KEVs with sensor-observed exploitation activity
The catalog gap matters for langflow-ai exposure
Four of the seven exploited langflow-ai CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 57% of this vendor portfolio.
- 43%
- Covered by CISA
- 57%
- Beyond CISA
- 2
- Product families
Attested langflow-ai CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-33497
Langflow: /profile_pictures/{folder_name}/{file_name} endpoint file reading |
langflow | Confirmed | Beyond CISA | 11 Aug 2026 |
|
CVE-2026-55450
Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak |
langflow | Confirmed | Beyond CISA | 09 Aug 2026 |
|
CVE-2024-37014
Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and provide... |
Langflow | Confirmed | Beyond CISA | 01 Aug 2026 |
|
CVE-2026-55255
Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow |
langflow | Confirmed | In CISA | 07 Jul 2026 |
|
CVE-2026-5027
Langflow - Path Traversal Arbitrary File Write via upload_user_file |
langflow | Confirmed | Beyond CISA | 10 Jun 2026 |
|
CVE-2026-33017
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint |
langflow | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-3248
Langflow Unauth RCE |
langflow | Confirmed | In CISA | 05 May 2025 |
No langflow-ai CVEs match this search or filter.
Showing 7 of 7 langflow-ai known exploited vulnerabilities.
Recurring weakness patterns
Missing authentication for critical function, control, and limitation account for seven mapped occurrences across this langflow-ai KEV portfolio.
CWE-306
Missing Authentication for Critical Function
CWE-94
Improper Control of Generation of Code ('Code Injection')
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-95
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
CWE-400
Uncontrolled Resource Consumption
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CWE-639
Authorization Bypass Through User-Controlled Key
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.