[← signals](https://highsignal.app/signals)

2026-07-30·[LANGFLOW](https://highsignal.app/entities/LANGFLOW)·devtool trust

highdown

# Multiple OSV advisories published in July 2026 reveal severe security vulnerabilities in Langflow, an open-source...

Multiple OSV advisories published in July 2026 reveal severe security vulnerabilities in Langflow, an open-source low-code AI development tool.

window 15devidence 11confidence score 100

sharecopy link

## confidence score

Strong evidence: 2 independent source classes support this read.

100

high confidence2 independent source classesotherpasses publish gate

## signal brief

Multiple OSV advisories published in July 2026 reveal severe security vulnerabilities in Langflow, an open-source low-code AI development tool. The disclosed issues include remote code execution (CVE-2024-48061, CVE-2026-0770), server-side request forgery (CVE-2025-68477), path traversal (CVE-2026-42867), missing authentication on critical API endpoints (CVE-2026-21445), and information leakage (CVE-2026-6597, CVE-2026-6598), among others. The vulnerabilities span CVE entries with high severity scores, impacting users who deploy Langflow in production or development environments. A dev release (1.12.0.dev10) was pushed to PyPI on July 30, but it is unclear whether it addresses all these issues. The breadth and depth of the flaws erode confidence in Langflow's security posture, potentially driving developers to alternative tools and slowing adoption in AI infrastructure workflows.

**What the sources said:**

- Source [PYSEC-2026-1523](https://osv.dev/vulnerability/PYSEC-2026-1523): 'Langflow vulnerable to remote code execution' (CVE-2024-48061).

- Source [PYSEC-2026-1525](https://osv.dev/vulnerability/PYSEC-2026-1525): 'Remote Code Execution via validate_code() exec()' (CVE-2026-0770).

- Source [PYSEC-2026-1522](https://osv.dev/vulnerability/PYSEC-2026-1522): 'Langflow vulnerable to Server-Side Request Forgery' (CVE-2025-68477).

- Source [PYSEC-2026-2569](https://osv.dev/vulnerability/PYSEC-2026-2569): 'Langflow vulnerable to injection' (CVE-2026-6599).

## source data used

package·2026-07-30·[pypi.org](https://pypi.org/project/langflow/)·[source day](https://highsignal.app/data/packages?date=2026-07-30)

“A Python package with a built-in web application”

osv·2026-07-07·[osv.dev](https://osv.dev/vulnerability/PYSEC-2026-1521)·[source day](https://highsignal.app/data/packages?date=2026-07-07)

“Aliases: CVE-2024-9277, GHSA-355v-2rjx-fpx7 Inefficient Regular Expression Complexity in langflow”

osv·2026-07-07·[osv.dev](https://osv.dev/vulnerability/PYSEC-2026-1522)·[source day](https://highsignal.app/data/packages?date=2026-07-07)

“Aliases: CVE-2025-68477, GHSA-5993-7p27-66g5 Langflow vulnerable to Server-Side Request Forgery”

osv·2026-07-07·[osv.dev](https://osv.dev/vulnerability/PYSEC-2026-1523)·[source day](https://highsignal.app/data/packages?date=2026-07-07)

“Aliases: CVE-2024-48061, GHSA-5p5r-57fx-pmfr Langflow vulnerable to remote code execution”

osv·2026-07-07·[osv.dev](https://osv.dev/vulnerability/PYSEC-2026-1524)·[source day](https://highsignal.app/data/packages?date=2026-07-07)

“Aliases: CVE-2026-21445, GHSA-c5cp-vx83-jhqx, PYSEC-2026-2571 Langflow Missing Authentication on Critical API Endpoints”

osv·2026-07-07·[osv.dev](https://osv.dev/vulnerability/PYSEC-2026-1525)·[source day](https://highsignal.app/data/packages?date=2026-07-07)

“Aliases: CVE-2026-0770, GHSA-g22f-v6f7-2hrh Langflow affected by Remote Code Execution via validate_code() exec()”

osv·2026-07-13·[osv.dev](https://osv.dev/vulnerability/PYSEC-2026-2565)·[source day](https://highsignal.app/data/packages?date=2026-07-13)

“Aliases: CVE-2026-6597, GHSA-5jjf-wcvf-923w Langflow has an Information Leak through Incomplete API Key Redaction”

osv·2026-07-13·[osv.dev](https://osv.dev/vulnerability/PYSEC-2026-2566)·[source day](https://highsignal.app/data/packages?date=2026-07-13)

“Aliases: CVE-2026-42867, GHSA-79ph-745m-6wxq Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint”

osv·2026-07-13·[osv.dev](https://osv.dev/vulnerability/PYSEC-2026-2567)·[source day](https://highsignal.app/data/packages?date=2026-07-13)

“Aliases: CVE-2026-34046, GHSA-8c4j-f57c-35cf, PYSEC-2026-2570 Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check”

osv·2026-07-13·[osv.dev](https://osv.dev/vulnerability/PYSEC-2026-2568)·[source day](https://highsignal.app/data/packages?date=2026-07-13)

“Aliases: CVE-2026-6598, GHSA-9jpj-cph8-w449 Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint”

osv·2026-07-13·[osv.dev](https://osv.dev/vulnerability/PYSEC-2026-2569)·[source day](https://highsignal.app/data/packages?date=2026-07-13)

“Aliases: CVE-2026-6599, GHSA-v66p-f7x3-4794 Langflow vulnerable to injection”

sharecopy link

Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.

## score history

window | return | outcome |

15d | — | pending |

---

Canonical HTML: https://highsignal.app/signals/langflow-critical-security-vulnerabilities-disclosed-in-langflow
