Between June 23 and July 20, 2026, the Open Source Vulnerabilities (OSV) database published 21 distinct security...
Between June 23 and July 20, 2026, the Open Source Vulnerabilities (OSV) database published 21 distinct security advisories for Langflow, an AI workflow tool.
confidence score
Strong evidence: 2 independent source classes support this read.
signal brief
Between June 23 and July 20, 2026, the Open Source Vulnerabilities (OSV) database published 21 distinct security advisories for Langflow, an AI workflow tool. The vulnerabilities range from Remote Code Execution (RCE) and Server-Side Request Forgery (SSRF) to Insecure Direct Object Reference (IDOR) and missing authentication on critical API endpoints. Notably, several advisories highlight unauthenticated RCE via the 'Shareable Playground' feature (PYSEC-2026-243, PYSEC-2026-244) and arbitrary file read (PYSEC-2026-2566). The volume and severity of these issues indicate systemic security weaknesses that could undermine user trust and enterprise adoption.
What the sources said:
- PYSEC-2026-243: 'Shareable Playground ... contains a critical RCE vulnerability. The vulnerable field is data.nodes[X].data.node.template.code.value.' Source
- PYSEC-2026-242: 'Any authenticated user can read, modify, rename, or permanently delete another user's data by supplying the target's resource ID.' Source
- PYSEC-2026-377: 'Langflow Knowledge Bases API is Vulnerable to Path Traversal.' Source
- PYSEC-2026-1523: 'Langflow vulnerable to remote code execution.' Source
The disclosure of over 20 CVEs in a short period signals a lack of security maturity in Langflow's development lifecycle. Enterprises using Langflow for AI agent deployment may face increased risk, potentially slowing adoption or prompting migration to more secure alternatives. The rapid issuance of fixes (up to version 1.11.0.dev49) suggests the vendor is responsive, but the breadth of vulnerabilities may damage long-term trust.
source data used
“A Python package with a built-in web application”
“Aliases: CVE-2024-9277, GHSA-355v-2rjx-fpx7 Inefficient Regular Expression Complexity in langflow”
“Aliases: CVE-2025-68477, GHSA-5993-7p27-66g5 Langflow vulnerable to Server-Side Request Forgery”
“Aliases: CVE-2024-48061, GHSA-5p5r-57fx-pmfr Langflow vulnerable to remote code execution”
“Aliases: CVE-2026-21445, GHSA-c5cp-vx83-jhqx, PYSEC-2026-2571 Langflow Missing Authentication on Critical API Endpoints”
“Aliases: CVE-2026-0770, GHSA-g22f-v6f7-2hrh Langflow affected by Remote Code Execution via validate_code() exec()”
“Aliases: CVE-2026-55255, GHSA-qrpv-q767-xqq2 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow...”
“Aliases: CVE-2026-55423, GHSA-7hw8-6q6r-4276 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.7.0, the logout button does not clear the session. The previous user stays logged in unless another user explicitly...”
“Aliases: CVE-2026-55446, GHSA-qwqc-p3q8-wcg9 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.0.19, an attacker can send a /api/v1/files/upload/ request without any authentication token/cookies and abuse a very long multipart form...”
“Aliases: CVE-2026-55450, GHSA-x223-p2gf-v735 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can upload any amount of data to the server without any limitations. No need for any...”
“Aliases: CVE-2026-33760, GHSA-9c59-2mvc-vfr8 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow's /api/v1/monitor router exposes 7 endpoints that perform read, write, and delete operations on user-owned resources — messages,...”
“Aliases: CVE-2026-48519, GHSA-v5ff-9q35-q26f Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, the "Shareable Playground" (or "Public Flows" in code) contains a critical RCE vulnerability. Shareable Playground feature works by...”
“Aliases: CVE-2026-48520, GHSA-rcjh-r59h-gq37 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.10.0, the "Shareable Playground" (or "Public Flows" in code) contains a potential arbitrary file-read vulnerability, depending on the exact...”
“Aliases: CVE-2026-6597, GHSA-5jjf-wcvf-923w Langflow has an Information Leak through Incomplete API Key Redaction”
“Aliases: CVE-2026-42867, GHSA-79ph-745m-6wxq Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint”
“Aliases: CVE-2026-34046, GHSA-8c4j-f57c-35cf, PYSEC-2026-2570 Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check”
“Aliases: CVE-2026-6598, GHSA-9jpj-cph8-w449 Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint”
“Aliases: CVE-2026-6599, GHSA-v66p-f7x3-4794 Langflow vulnerable to injection”
“Aliases: CVE-2026-27966, GHSA-3645-fxcv-hqr4 Langflow has Remote Code Execution in CSV Agent”
“Aliases: CVE-2026-42048, GHSA-9whx-c884-c68q Langflow Knowledge Bases API is Vulnerable to Path Traversal”
“Aliases: CVE-2026-55447, GHSA-ccv6-r384-xp75 Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit”
“Aliases: CVE-2026-33017, GHSA-vwmf-pq79-vjvx Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint”
Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.