Between July 7 and July 13, 2026, the OSV database published at least 10 distinct advisories against Langflow, an...
Between July 7 and July 13, 2026, the OSV database published at least 10 distinct advisories against Langflow, an open-source low-code platform for building LLM applications.
confidence score
Strong evidence: 2 independent source classes support this read.
signal brief
Between July 7 and July 13, 2026, the OSV database published at least 10 distinct advisories against Langflow, an open-source low-code platform for building LLM applications. The most severe include Remote Code Execution via validate_code() (PYSEC-2026-1525, CVE-2026-0770), Missing Authentication on Critical API Endpoints (PYSEC-2026-1524, CVE-2026-21445), Server-Side Request Forgery (PYSEC-2026-1522, CVE-2025-68477), and a generic injection vulnerability (PYSEC-2026-2569, CVE-2026-6599). Additional advisories cover path traversal in the Knowledge Bases API (PYSEC-2026-2566), an authorization bypass letting authenticated users read/modify/delete any flow (PYSEC-2026-2567), cleartext storage of authentication settings (PYSEC-2026-2568), and API key redaction leakage (PYSEC-2026-2565). The breadth of these flaws – from unauthenticated access to RCE to injection – indicates systemic security debt rather than isolated defects. For AI-infrastructure teams running Langflow in production, these advisories create elevated risk of data exfiltration, privileged abuse, and supply-chain compromise through a trusted devtool. Adoption of Langflow in regulated enterprises is likely to slow as security teams reassess. A dev release (1.12.0.dev14) appeared on PyPI on Aug 3 (source), but no stable security patch is publicly tied to these advisories in the source set.
What the sources said
- "Langflow affected by Remote Code Execution via validate_code() exec()" — OSV PYSEC-2026-1525
- "Langflow Missing Authentication on Critical API Endpoints" — OSV PYSEC-2026-1524
- "Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint" — OSV PYSEC-2026-2566
- "Langflow vulnerable to injection" — OSV PYSEC-2026-2569
source data used
“A Python package with a built-in web application”
“Aliases: CVE-2024-9277, GHSA-355v-2rjx-fpx7 Inefficient Regular Expression Complexity in langflow”
“Aliases: CVE-2025-68477, GHSA-5993-7p27-66g5 Langflow vulnerable to Server-Side Request Forgery”
“Aliases: CVE-2024-48061, GHSA-5p5r-57fx-pmfr Langflow vulnerable to remote code execution”
“Aliases: CVE-2026-21445, GHSA-c5cp-vx83-jhqx, PYSEC-2026-2571 Langflow Missing Authentication on Critical API Endpoints”
“Aliases: CVE-2026-0770, GHSA-g22f-v6f7-2hrh Langflow affected by Remote Code Execution via validate_code() exec()”
“Aliases: CVE-2026-6597, GHSA-5jjf-wcvf-923w Langflow has an Information Leak through Incomplete API Key Redaction”
“Aliases: CVE-2026-42867, GHSA-79ph-745m-6wxq Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint”
“Aliases: CVE-2026-34046, GHSA-8c4j-f57c-35cf, PYSEC-2026-2570 Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check”
“Aliases: CVE-2026-6598, GHSA-9jpj-cph8-w449 Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint”
“Aliases: CVE-2026-6599, GHSA-v66p-f7x3-4794 Langflow vulnerable to injection”
Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.