Langflow, the open-source low-code AI workflow builder, has accumulated a critical security backlog.
Langflow, the open-source low-code AI workflow builder, has accumulated a critical security backlog.
confidence score
Strong evidence: 3 independent source classes support this read.
signal brief
Langflow, the open-source low-code AI workflow builder, has accumulated a critical security backlog. On 2026-08-04, CISA added CVE-2026-9198 to its Known Exploited Vulnerabilities catalog, describing a code injection that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. CISA gave a due date of 2026-08-07, forcing federal agencies and BOD 26-04-covered organizations to patch or discontinue use within days (CISA KEV). This follows a wave of OSV advisories published 2026-07-13: incomplete API key redaction (CVE-2026-6597), path traversal in the Knowledge Bases API (CVE-2026-42867), missing ownership checks letting authenticated users read/modify/delete any flow (CVE-2026-34046), cleartext storage of authentication settings (CVE-2026-6598), and an additional injection flaw (CVE-2026-6599) (OSV PYSEC-2026-2565, PYSEC-2026-2566, PYSEC-2026-2567, PYSEC-2026-2568, PYSEC-2026-2569). Active development continues, with a dev build released on PyPI on 2026-08-09 (PyPI langflow), but the cluster of critical flaws suggests security debt that could slow enterprise deployment of AI agents built on Langflow. The signal direction is negative for Langflow: CISA KEV status and multiple unpatched or recently patched vulnerabilities raise the risk of enterprise churn, stricter procurement review, and a dampened developer trust, especially given the project's role as a UI/orchestration layer in AI stacks. while no direct competitors were named in the supplied sources, Langflow's security posture will influence the low-code AI tooling segment broadly.
What the sources said:
- CISA: "Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments." (source)
- OSV PYSEC-2026-2566: "Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint" (source)
- OSV PYSEC-2026-2567: "Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check" (source)
source data used
“CVE: CVE-2026-9198 Vendor/project: IBM Product: Langflow Known ransomware campaign use: Unknown Due date: 2026-08-07 CWE: CWE-94 Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments....”
“A Python package with a built-in web application”
“Aliases: CVE-2026-6597, GHSA-5jjf-wcvf-923w Langflow has an Information Leak through Incomplete API Key Redaction”
“Aliases: CVE-2026-42867, GHSA-79ph-745m-6wxq Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint”
“Aliases: CVE-2026-34046, GHSA-8c4j-f57c-35cf, PYSEC-2026-2570 Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check”
“Aliases: CVE-2026-6598, GHSA-9jpj-cph8-w449 Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint”
“Aliases: CVE-2026-6599, GHSA-v66p-f7x3-4794 Langflow vulnerable to injection”
Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.