Multiple critical security vulnerabilities have been disclosed in Langflow, a popular open-source visual framework for...
Multiple critical security vulnerabilities have been disclosed in Langflow, a popular open-source visual framework for building LLM-based applications.
confidence score
Strong evidence: 3 independent source classes support this read.
signal brief
Multiple critical security vulnerabilities have been disclosed in Langflow, a popular open-source visual framework for building LLM-based applications. The most severe is CVE-2026-0770, a remote code execution vulnerability via inclusion of functionality from an untrusted control sphere, which was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on July 21, 2026, indicating active exploitation. CISA mandates patching by July 24, 2026, per BOD 26-04. Additionally, OSV advisories published between June 29 and July 13, 2026, catalog at least 12 other vulnerabilities, including RCE via CSV Agent (CVE-2026-27966), path traversal in Knowledge Bases API (CVE-2026-42867), authentication bypass (CVE-2026-21445), and SSRF (CVE-2025-68477). A PyPI dev release (1.12.0.dev5) on July 25 suggests ongoing patching efforts. The volume and severity of vulnerabilities, coupled with confirmed exploitation, severely damage developer trust and adoption prospects for Langflow, particularly in enterprise and security-conscious AI deployments. Organizations using Langflow face urgent patching requirements and may reconsider its use.
What the sources said
- CISA: 'Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.' (https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-0770)
- OSV advisory PYSEC-2026-1525: 'Langflow affected by Remote Code Execution via validate_code() exec()' (https://osv.dev/vulnerability/PYSEC-2026-1525)
- OSV advisory PYSEC-2026-2566: 'Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint' (https://osv.dev/vulnerability/PYSEC-2026-2566)
- OSV advisory PYSEC-2026-2567: 'Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check' (https://osv.dev/vulnerability/PYSEC-2026-2567)
source data used
“CVE: CVE-2026-0770 Vendor/project: Langflow Product: Langflow Known ransomware campaign use: Unknown Due date: 2026-07-24 CWE: CWE-829 Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on...”
“A Python package with a built-in web application”
“Aliases: CVE-2024-9277, GHSA-355v-2rjx-fpx7 Inefficient Regular Expression Complexity in langflow”
“Aliases: CVE-2025-68477, GHSA-5993-7p27-66g5 Langflow vulnerable to Server-Side Request Forgery”
“Aliases: CVE-2024-48061, GHSA-5p5r-57fx-pmfr Langflow vulnerable to remote code execution”
“Aliases: CVE-2026-21445, GHSA-c5cp-vx83-jhqx, PYSEC-2026-2571 Langflow Missing Authentication on Critical API Endpoints”
“Aliases: CVE-2026-0770, GHSA-g22f-v6f7-2hrh Langflow affected by Remote Code Execution via validate_code() exec()”
“Aliases: CVE-2026-6597, GHSA-5jjf-wcvf-923w Langflow has an Information Leak through Incomplete API Key Redaction”
“Aliases: CVE-2026-42867, GHSA-79ph-745m-6wxq Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint”
“Aliases: CVE-2026-34046, GHSA-8c4j-f57c-35cf, PYSEC-2026-2570 Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check”
“Aliases: CVE-2026-6598, GHSA-9jpj-cph8-w449 Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint”
“Aliases: CVE-2026-6599, GHSA-v66p-f7x3-4794 Langflow vulnerable to injection”
“Aliases: CVE-2026-27966, GHSA-3645-fxcv-hqr4 Langflow has Remote Code Execution in CSV Agent”
“Aliases: CVE-2026-42048, GHSA-9whx-c884-c68q Langflow Knowledge Bases API is Vulnerable to Path Traversal”
“Aliases: CVE-2026-55447, GHSA-ccv6-r384-xp75 Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit”
“Aliases: CVE-2026-33017, GHSA-vwmf-pq79-vjvx Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint”
Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.