17 Total CVEs
17 AI Analyzed
2 CISA KEV
9 Critical

Profile

11.8% ended up actively exploited 2 of 17 added to CISA KEV
53% rated critical (CVSS 9.0+) 9 critical, 8 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

16 CVEs in the last 12 months

Products

  • Langflow6
  • langflow2
  • Actions workflows1

3 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-17 of 17 CVEs
CVE-2026-6596
Analyzed
7.3
langflow-ai langflow

A security flaw has been discovered in langflow-ai langflow up to 1

2026-04-20
CVE-2026-55450
Analyzed
9.3
langflow-ai langflow

Unauthenticated users can exploit Langflow to cause server-side space exhaustion via excessive file uploads and gain information leaks regarding file...

2026-06-24
CVE-2026-55447
Analyzed
9.6
langflow-ai Langflow

A path traversal vulnerability in Langflow components based on BaseFileComponent allows attackers to read arbitrary files from the server's filesystem...

2026-06-24
CVE-2026-55255
KEV Analyzed
9.9
langflow-ai Langflow

An Insecure Direct Object Reference (IDOR) vulnerability in the Langflow /api/v1/responses endpoint allows authenticated attackers to execute unauthor...

2026-06-24
CVE-2026-5027
Analyzed
8.8
langflow-ai Multiple Products

The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbi...

2026-03-28
CVE-2026-48519
Analyzed
9.6
langflow-ai Langflow

Langflow contains a critical remote code execution (RCE) vulnerability in its "Shareable Playground" feature, allowing unauthenticated users to execut...

2026-06-24
CVE-2026-42048
Analyzed
9.6
langflow-ai Multiple Products

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowled...

2026-05-13
CVE-2026-33760
Analyzed
8.8
langflow-ai Langflow

Langflow is a tool for building and deploying AI-powered agents and workflows

2026-06-24
CVE-2026-33484
Analyzed
7.5
langflow-ai Multiple Products

Langflow is a tool for building and deploying AI-powered agents and workflows

2026-03-26
CVE-2026-33475
Analyzed
9.1
langflow-ai Actions workflows

Unauthenticated remote shell injection in Langflow's GitHub Actions workflows allows attackers to execute arbitrary commands and exfiltrate CI secrets...

2026-03-25
CVE-2026-33309
Analyzed
9.9
langflow-ai Multiple Products

Langflow is a tool for building and deploying AI-powered agents and workflows. Versions 1.2.0 through 1.8.1 have a bypass of the patch for CVE-2025-68...

2026-03-25
CVE-2026-33053
Analyzed
8.8
langflow-ai Multiple Products

Langflow is a tool for building and deploying AI-powered agents and workflows

2026-03-21
CVE-2026-33017
KEV Analyzed
9.5
langflow-ai Langflow

Langflow Code Injection Vulnerability - Active in CISA KEV catalog.

2026-03-26
CVE-2026-27966
Analyzed
9.8
langflow-ai Langflow

Langflow's CSV Agent node improperly enables dangerous code execution by default, allowing unauthenticated attackers to achieve remote code execution...

2026-02-27
CVE-2025-68478
Analyzed
7.1
langflow-ai Multiple Products

Langflow is a tool for building and deploying AI-powered agents and workflows

2025-12-20
CVE-2025-68477
Analyzed
7.7
langflow-ai Multiple Products

Langflow is a tool for building and deploying AI-powered agents and workflows

2025-12-20
CVE-2025-57760
Analyzed
8.8
langflow-ai Multiple Products

Langflow is a tool for building and deploying AI-powered agents and workflows

2025-08-25