Loading...
Skip to main content
PyPI (Python)

langflow Security Analysis

langflow has 19 known security vulnerabilities in PyPI (Python). Upgrade to version 1.9.2 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.

19 Vulnerabilities

Actively Exploited

CISA has confirmed this package has vulnerabilities under active exploitation. Prioritize updating immediately.

Recommended safe version: 1.9.2

Upgrading to 1.9.2 or later resolves all 19 known vulnerabilities in langflow. Run: pip install "langflow>=1.9.2"

Is langflow in your project?

Check if you're affected and upgrade to 1.9.2 to stay secure.

19
Total
0
Critical
0
High
0
Medium
0
Low

Active Exploitation Warning

One or more vulnerabilities in this package are known to be actively exploited in the wild. Immediate action is recommended.

Vulnerabilities

19 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.

CVE / GHSASeverityAffectedFixed In
CVE-2026-0770
Langflow affected by Remote Code Execution via validate_code() exec()
CRITICAL
0.0.31, 0.0.32, 0.0.33, 0.0.40 (+276 more)No fix available
CVE-2026-33017
Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint
CRITICAL
0.0.31, 0.0.32, 0.0.33, 0.0.40 (+289 more)1.9.0
CVE-2024-48061
Langflow vulnerable to remote code execution
CRITICAL
0.0.31, 0.0.32, 0.0.33, 0.0.40 (+239 more)No fix available
CVE-2026-27966
Langflow has Remote Code Execution in CSV Agent
CRITICAL
0.0.31, 0.0.32, 0.0.33, 0.0.40 (+279 more)No fix available
CVE-2026-33309
Langflow has an Arbitrary File Write (RCE) via v2 API
CRITICAL
1.2.0, 1.3.0, 1.3.1, 1.3.2 (+37 more)1.9.0
CVE-2026-33017
Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint
CRITICAL
0.0.31, 0.0.32, 0.0.33, 0.0.40 (+289 more)1.9.0
CVE-2026-27966
Langflow has Remote Code Execution in CSV Agent
CRITICAL
0.0.31, 0.0.32, 0.0.33, 0.0.40 (+279 more)No fix available
CVE-2026-55447
Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
CRITICAL
0.0.31, 0.0.32, 0.0.33, 0.0.40 (+291 more)1.9.2
CVE-2026-42048
Langflow Knowledge Bases API is Vulnerable to Path Traversal
CRITICAL
0.0.31, 0.0.32, 0.0.33, 0.0.40 (+289 more)1.9.0
CVE-2026-55447
Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
CRITICAL
0.0.31, 0.0.32, 0.0.33, 0.0.40 (+291 more)1.9.2
CVE-2026-48519
Langflow: Unauthenticated RCE in Shareable Playgrounds
CRITICAL
0.0.31, 0.0.32, 0.0.33, 0.0.40 (+291 more)1.9.2
CVE-2026-42048
Langflow Knowledge Bases API is Vulnerable to Path Traversal
CRITICAL
0.0.31, 0.0.32, 0.0.33, 0.0.40 (+289 more)1.9.0
CVE-2026-33873
Langflow has Authenticated Code Execution in Agentic Assistant Validation
CRITICAL
0.0.31, 0.0.32, 0.0.33, 0.0.40 (+289 more)1.9.0
CVE-2026-55450
Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
CRITICAL
0.0.31, 0.0.32, 0.0.33, 0.0.40 (+290 more)1.9.1
CVE-2026-21445
Langflow Missing Authentication on Critical API Endpoints
CRITICAL
0.0.31, 0.0.32, 0.0.33, 0.0.40 (+273 more)1.7.1
CVE-2026-0770
Langflow affected by Remote Code Execution via validate_code() exec()
HIGH
0.0.31, 0.0.32, 0.0.33, 0.0.40 (+276 more)No fix available
CVE-2024-42835
langflow has vulnerability in PythonCodeTool component
HIGH
0.0.31, 0.0.32, 0.0.33, 0.0.40 (+233 more)No fix available
CVE-2026-21445
Langflow Missing Authentication on Critical API Endpoints
HIGH
0.0.31, 0.0.32, 0.0.33, 0.0.40 (+273 more)1.7.1
CVE-2024-48061
Langflow vulnerable to remote code execution
MEDIUM
0.0.31, 0.0.32, 0.0.33, 0.0.40 (+239 more)No fix available

About This Data

Vulnerability data for langflow is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.

CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Related PyPI (Python) Packages

Other packages in this ecosystem, ranked by shared vulnerabilities where available.

Check Your Dependencies

Scan your project to check if you're using a vulnerable version of langflow.

Data from OSV DatabaseUpdated daily200K+ vulnerabilities indexed