← signals
2026-07-25·LANGFLOW·security risk
highdown

Multiple critical security vulnerabilities have been disclosed in Langflow, a popular open-source visual framework for...

Multiple critical security vulnerabilities have been disclosed in Langflow, a popular open-source visual framework for building LLM-based applications.

window 14devidence 16confidence score 100

confidence score

Strong evidence: 3 independent source classes support this read.

100
high confidence3 independent source classesofficialotherpasses publish gate

signal brief

Multiple critical security vulnerabilities have been disclosed in Langflow, a popular open-source visual framework for building LLM-based applications. The most severe is CVE-2026-0770, a remote code execution vulnerability via inclusion of functionality from an untrusted control sphere, which was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on July 21, 2026, indicating active exploitation. CISA mandates patching by July 24, 2026, per BOD 26-04. Additionally, OSV advisories published between June 29 and July 13, 2026, catalog at least 12 other vulnerabilities, including RCE via CSV Agent (CVE-2026-27966), path traversal in Knowledge Bases API (CVE-2026-42867), authentication bypass (CVE-2026-21445), and SSRF (CVE-2025-68477). A PyPI dev release (1.12.0.dev5) on July 25 suggests ongoing patching efforts. The volume and severity of vulnerabilities, coupled with confirmed exploitation, severely damage developer trust and adoption prospects for Langflow, particularly in enterprise and security-conscious AI deployments. Organizations using Langflow face urgent patching requirements and may reconsider its use.

What the sources said

  • CISA: 'Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.' (https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-0770)
  • OSV advisory PYSEC-2026-1525: 'Langflow affected by Remote Code Execution via validate_code() exec()' (https://osv.dev/vulnerability/PYSEC-2026-1525)
  • OSV advisory PYSEC-2026-2566: 'Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint' (https://osv.dev/vulnerability/PYSEC-2026-2566)
  • OSV advisory PYSEC-2026-2567: 'Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check' (https://osv.dev/vulnerability/PYSEC-2026-2567)

source data used

Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.