Langflow, an open-source AI workflow tool, is facing a concentrated security crisis.
Langflow, an open-source AI workflow tool, is facing a concentrated security crisis.
confidence score
Strong evidence: 3 independent source classes support this read.
signal brief
Langflow, an open-source AI workflow tool, is facing a concentrated security crisis. On 2026-08-04, CISA added CVE-2026-9198 to its Known Exploited Vulnerabilities catalog, warning that the product contains a code injection vulnerability allowing unauthenticated attackers to achieve full remote code execution on default deployments. The required action mandates patching by 2026-08-07 per BOD 26-04. This is not an isolated event: between 2026-07-13 and 2026-07-14, OSV recorded five additional Langflow advisories (PYSEC-2026-2565 through 2569) covering information leaks (incomplete API key redaction), path traversal in the Knowledge Bases API, missing ownership checks letting authenticated users read/modify/delete any flow, cleartext storage of authentication settings, and an injection vulnerability. The rapid cascade of CVEs — all at pre-1.0 or dev-level maturity for the project — signals serious security engineering debt. For enterprises adopting Langflow for AI orchestration pipelines, this creates immediate compliance and operational risk. The CISA KEV inclusion strongly increases the likelihood of ransomware-style exploitation attempts, forcing urgent patching cycles or product replacement. The PyPI release of langflow 1.12.0.dev20 on 2026-08-08 shows active development, but the sheer volume of unresolved security flaws undermines trust in the project's production-readiness. Direction is down for Langflow's enterprise adoption and developer trust; the vulnerabilities point to a widening security gap that competitors can exploit.
What the sources said
- CISA: "Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments." (https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-9198)
- OSV PYSEC-2026-2567: "Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check." (https://osv.dev/vulnerability/PYSEC-2026-2567)
- OSV PYSEC-2026-2565: "Langflow has an Information Leak through Incomplete API Key Redaction." (https://osv.dev/vulnerability/PYSEC-2026-2565)
- PyPI: "langflow 1.12.0.dev20 — A Python package with a built-in web application." (https://pypi.org/project/langflow/)
source data used
“CVE: CVE-2026-9198 Vendor/project: IBM Product: Langflow Known ransomware campaign use: Unknown Due date: 2026-08-07 CWE: CWE-94 Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments....”
“A Python package with a built-in web application”
“Aliases: CVE-2026-6597, GHSA-5jjf-wcvf-923w Langflow has an Information Leak through Incomplete API Key Redaction”
“Aliases: CVE-2026-42867, GHSA-79ph-745m-6wxq Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint”
“Aliases: CVE-2026-34046, GHSA-8c4j-f57c-35cf, PYSEC-2026-2570 Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check”
“Aliases: CVE-2026-6598, GHSA-9jpj-cph8-w449 Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint”
“Aliases: CVE-2026-6599, GHSA-v66p-f7x3-4794 Langflow vulnerable to injection”
Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.