Langflow
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 39 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from June 10, 2024 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Langflow: Path Traversal in Langflow Knowledge Bases API
Unauthenticated Insecure Direct Object Reference (IDOR) Vulnerability in Langflow Desktop Image Download Endpoint
Stored Cross-Site Scripting (XSS) in Langflow Markdown Rendering via rehypeRaw
Server-Side Request Forgery (SSRF) in Langflow URL Component
Arbitrary File Write and Remote Code Execution Vulnerability in Langflow v2 API
Authenticated Remote Code Execution Vulnerability in Langflow Code Validation Endpoint
Path Traversal and Arbitrary File Write Vulnerability in IBM Langflow Desktop API v2 File Upload Endpoint
Monitor API allows cross-user read of transaction logs and deletion of build data via flow_id
IBM Langflow Desktop FAISS Vector Store Remote Code Execution via malicious Pickle file
Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check
Monitor Langflow in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.