Ibm Langflow Oss vulnerabilities
141 known vulnerabilities affecting ibm/langflow_oss.
Total CVEs
141
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL36HIGH73MEDIUM32
Vulnerabilities
Page 5 of 8
CVE-2026-18899P3HIGHCVSS 7.5≥ 1.0.0, ≤ 1.11.12026-08-28
CVE-2026-18899 [HIGH] CWE-22 CVE-2026-18899: IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbitrary files due to p
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbitrary files due to path traversal.
nvd
CVE-2026-10564P3HIGHCVSS 8.2≥ 1.0.0, ≤ 1.9.62026-06-30
CVE-2026-10564 [HIGH] CWE-918 CVE-2026-10564: IBM Langflow OSS 1.0.0 through 1.9.6 contains a Server-Side Request Forgery (SSRF). The legacy RSSRe
IBM Langflow OSS 1.0.0 through 1.9.6 contains a Server-Side Request Forgery (SSRF). The legacy RSSReaderComponent in rss.py and SearXNG component in searxng.py make unvalidated HTTP requests to user-controlled URLs, bypassing SSRF protections introduced in version 1.9.3. An authenticated attacker can exploit this to access internal resources including
nvd
CVE-2026-13444P3HIGHCVSS 8.1≥ 1.0.0, ≤ 1.10.12026-07-30
CVE-2026-13444 [HIGH] CWE-520 CVE-2026-13444: IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector
IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents by creating their own flow with matching Chroma persist_directory and collection_name values. The attacker receives exact victim content in their workflow output despite having no authorization to read the victim's flow. Additionally, the attac
nvd
CVE-2026-93445P3HIGHCVSS 8.1≥ 1.0.0, ≤ 1.12.22026-10-07
CVE-2026-93445 [HIGH] CWE-94 CVE-2026-93445: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitra
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.
nvd
CVE-2026-81213P3HIGHCVSS 8.6≥ 1.0.0, ≤ 1.11.52026-09-10
CVE-2026-81213 [HIGH] CWE-918 CVE-2026-81213: IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of user-supplied URLs.
nvd
CVE-2026-19303P3HIGHCVSS 8.1≥ 1.0.0, ≤ 1.11.22026-09-04
CVE-2026-19303 [HIGH] CWE-22 CVE-2026-19303: IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrar
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrary local files or directories due to improper limitation of a pathname to a restricted directory.
nvd
CVE-2026-8446P3HIGHCVSS 7.5≥ 1.0.0, ≤ 1.10.32026-08-05
CVE-2026-8446 [HIGH] CWE-306 CVE-2026-8446: IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Co
IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP) composer endpoint when mcp_composer_enabled=true (default) and projects are configured with auth_type=oauth .
nvd
CVE-2026-9205P3CRITICALCVSS 9.8≥ 1.0.0, ≤ 1.10.32026-08-05
CVE-2026-9205 [CRITICAL] CWE-338 CVE-2026-9205: IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key
IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.
nvd
CVE-2026-93443P3HIGHCVSS 7.5≥ 1.0.0, ≤ 1.12.22026-10-07
CVE-2026-93443 [HIGH] CWE-94 CVE-2026-93443: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitra
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in code.
nvd
CVE-2026-93447P3HIGHCVSS 7.5≥ 1.0.0, ≤ 1.12.22026-10-07
CVE-2026-93447 [HIGH] CWE-502 CVE-2026-93447: IBM Langflow OSS 1.0.0 through 1.12.2 could allow an attacker with access to the server secret and R
IBM Langflow OSS 1.0.0 through 1.12.2 could allow an attacker with access to the server secret and Redis write access to submit a malicious serialized cache value. When the value was retrieved, deserialization could have executed attacker-controlled code with the privileges of the service process.
nvd
CVE-2026-81268P3HIGHCVSS 8.1≥ 1.0.0, ≤ 1.11.52026-09-10
CVE-2026-81268 [HIGH] CWE-613 CVE-2026-81268: IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows a
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation.
nvd
CVE-2026-10547P3HIGHCVSS 8.1≥ 1.0.0, ≤ 1.10.32026-08-05
CVE-2026-10547 [HIGH] CWE-284 CVE-2026-10547: IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /a
IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/vertices endpoint, allowing an authenticated user to inject arbitrary graph data into a shared cache for any flow. This may result in cross-user cache pollution, unauthorized workflow execution, or denial of service.
nvd
CVE-2026-6542P3HIGHCVSS 8.1≥ 1.0.0, ≤ 1.8.42026-04-30
CVE-2026-6542 [HIGH] CWE-639 CVE-2026-6542: IBM Langflow OSS 1.0.0 through 1.8.4 could allow any user to supply a flow_id to read transaction lo
IBM Langflow OSS 1.0.0 through 1.8.4 could allow any user to supply a flow_id to read transaction logs and vertex build data belonging to other users, and to delete persisted vertex build data for another user's flow.
nvd
CVE-2026-10700P3MEDIUMCVSS 6.5≥ 1.0.0, ≤ 1.8.42026-07-30
CVE-2026-10700 [MEDIUM] CWE-639 CVE-2026-10700: IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its
IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API that allow unauthorized access to user files.The /api/v1/files/images/{flow_id}/{file_name} endpoint does not enforce authentication or authorization checks, allowing unauthenticated remote attackers to retrieve image files associated
nvd
CVE-2026-97680P3HIGHCVSS 8.3≥ 1.0.0, ≤ 1.12.22026-10-07
CVE-2026-97680 [HIGH] CWE-284 CVE-2026-97680: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitiv
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information or inject malicious data due to improper access control in the vertex result caching subsystem.
nvd
CVE-2026-7787P3HIGHCVSS 8.1≥ 1.0.0, ≤ 1.9.12026-06-11
CVE-2026-7787 [HIGH] CWE-639 CVE-2026-7787: IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive i
IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information by bypassing authentication using insecure direct object references.
nvd
CVE-2026-9138P3MEDIUMCVSS 6.5≥ 1.0.0, ≤ 1.11.22026-09-04
CVE-2026-9138 [MEDIUM] CWE-22 CVE-2026-9138: IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write arbitr
IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write arbitrary files to the server due to improper input validation in the SaveToFileComponent. The application constructs local file paths using attacker‑controlled input without sufficient sanitization when handling requests to the /api/v1/run/{flow_id} endpoint.
nvd
CVE-2026-103360P3HIGHCVSS 8.1≥ 1.0.0, ≤ 1.12.22026-10-07
CVE-2026-103360 [HIGH] CWE-22 CVE-2026-103360: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitiv
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
nvd
CVE-2026-7646P3MEDIUMCVSS 6.5≥ 1.0.0, ≤ 1.10.32026-08-05
CVE-2026-7646 [MEDIUM] CWE-22 CVE-2026-7646: IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesyste
IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other users' uploaded documents, the JWT signing secret, the SQLite database, and process environment variables, by sending a crafted MCP `resources/read` request with a URL-encoded path traversal sequence in the filename.
nvd
CVE-2026-18904P3HIGHCVSS 8.2≥ 1.0.0, ≤ 1.11.12026-08-28
CVE-2026-18904 [HIGH] CWE-639 CVE-2026-18904: IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject unauthorized messages due to a namespace collision between user identifiers.
nvd