Langflow, an open-source visual AI workflow builder, has disclosed a wave of critical security vulnerabilities in...
Langflow, an open-source visual AI workflow builder, has disclosed a wave of critical security vulnerabilities in June-July 2026, as recorded in multiple OSV advisories.
confidence score
Strong evidence: 2 independent source classes support this read.
signal brief
Langflow, an open-source visual AI workflow builder, has disclosed a wave of critical security vulnerabilities in June-July 2026, as recorded in multiple OSV advisories. The issues range from remote code execution (RCE) via validate_code() source 6 and CSV Agent source 12 to server-side request forgery source 3, path traversal in Knowledge Bases API source 8 and source 13, missing authentication on critical API endpoints source 5, and cleartext storage of authentication settings source 10. These vulnerabilities could allow attackers to execute arbitrary code, access sensitive data, or completely compromise Langflow instances. Notably, CVE-2024-9277 describes an inefficient regex complexity that could lead to denial of service source 2. A development release (1.12.0.dev8) was published on PyPI shortly after the advisories source 1, suggesting an ongoing fix effort, but the scale and severity of these issues erode user trust and raise adoption risk for enterprises relying on Langflow for production AI workflows.
What the sources said
- OSV advisory PYSEC-2026-1525: "Langflow affected by Remote Code Execution via validate_code() exec()"
- Advisory PYSEC-2026-1524: "Langflow Missing Authentication on Critical API Endpoints"
- Advisory PYSEC-2026-2569: "Langflow vulnerable to injection"
- PyPI release 1.12.0.dev8 published on 2026-07-28, likely containing security patches.
source data used
“A Python package with a built-in web application”
“Aliases: CVE-2024-9277, GHSA-355v-2rjx-fpx7 Inefficient Regular Expression Complexity in langflow”
“Aliases: CVE-2025-68477, GHSA-5993-7p27-66g5 Langflow vulnerable to Server-Side Request Forgery”
“Aliases: CVE-2024-48061, GHSA-5p5r-57fx-pmfr Langflow vulnerable to remote code execution”
“Aliases: CVE-2026-21445, GHSA-c5cp-vx83-jhqx, PYSEC-2026-2571 Langflow Missing Authentication on Critical API Endpoints”
“Aliases: CVE-2026-0770, GHSA-g22f-v6f7-2hrh Langflow affected by Remote Code Execution via validate_code() exec()”
“Aliases: CVE-2026-6597, GHSA-5jjf-wcvf-923w Langflow has an Information Leak through Incomplete API Key Redaction”
“Aliases: CVE-2026-42867, GHSA-79ph-745m-6wxq Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint”
“Aliases: CVE-2026-34046, GHSA-8c4j-f57c-35cf, PYSEC-2026-2570 Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check”
“Aliases: CVE-2026-6598, GHSA-9jpj-cph8-w449 Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint”
“Aliases: CVE-2026-6599, GHSA-v66p-f7x3-4794 Langflow vulnerable to injection”
“Aliases: CVE-2026-27966, GHSA-3645-fxcv-hqr4 Langflow has Remote Code Execution in CSV Agent”
“Aliases: CVE-2026-42048, GHSA-9whx-c884-c68q Langflow Knowledge Bases API is Vulnerable to Path Traversal”
“Aliases: CVE-2026-55447, GHSA-ccv6-r384-xp75 Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit”
“Aliases: CVE-2026-33017, GHSA-vwmf-pq79-vjvx Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint”
Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.