Ibm Langflow Oss vulnerabilities
141 known vulnerabilities affecting ibm/langflow_oss.
Total CVEs
141
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL36HIGH73MEDIUM32
Vulnerabilities
Page 7 of 8
CVE-2026-19301P3MEDIUMCVSS 6.5≥ 1.0.0, ≤ 1.11.22026-09-04
CVE-2026-19301 [MEDIUM] CWE-918 CVE-2026-19301: IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitiv
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery.
nvd
CVE-2026-12767P3MEDIUMCVSS 6.5≥ 1.0.0, ≤ 1.11.52026-09-14
CVE-2026-12767 [MEDIUM] CWE-918 CVE-2026-12767: IBM Langflow OSS 1.0.0 through 1.11.5 is vulnerable to server-side request forgery (SSRF). This may
IBM Langflow OSS 1.0.0 through 1.11.5 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
nvd
CVE-2026-17631P3MEDIUMCVSS 6.5≥ 1.0.0, ≤ 1.10.22026-09-04
CVE-2026-17631 [MEDIUM] CWE-918 CVE-2026-17631: IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitiv
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability.
nvd
CVE-2026-7869P3MEDIUMCVSS 5.4≥ 1.0.0, ≤ 1.10.32026-08-05
CVE-2026-7869 [MEDIUM] CWE-22 CVE-2026-7869: IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`P
IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledge_bases`). This occurs because user-supplied knowledge base names are used directly to create file paths without proper sanitization or containment checks. An authenticated attacker can exploit this flaw to create directories and writ
nvd
CVE-2026-17621P3MEDIUMCVSS 5.4≥ 1.0.0, ≤ 1.10.22026-09-04
CVE-2026-17621 [MEDIUM] CWE-22 CVE-2026-17621: IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse directories on the s
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary files on the system.
nvd
CVE-2026-7528P3HIGHCVSS 7.5≥ 1.0.0, ≤ 1.9.02026-05-27
CVE-2026-7528 [HIGH] CWE-400 CVE-2026-7528: IBM Langflow OSS 1.0.0 through 1.9.0 could allow a denial of service due to uncontrolled resource co
IBM Langflow OSS 1.0.0 through 1.9.0 could allow a denial of service due to uncontrolled resource consumption.
nvd
CVE-2026-19302P3MEDIUMCVSS 6.5≥ 1.0.0, ≤ 1.11.22026-09-04
CVE-2026-19302 [MEDIUM] CWE-22 CVE-2026-19302: IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitiv
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.
nvd
CVE-2026-17622P3MEDIUMCVSS 6.5≥ 1.0.0, ≤ 1.10.22026-09-04
CVE-2026-17622 [MEDIUM] CWE-22 CVE-2026-17622: IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitiv
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
nvd
CVE-2026-19299P3MEDIUMCVSS 6.5≥ 1.0.0, ≤ 1.11.22026-09-04
CVE-2026-19299 [MEDIUM] CWE-22 CVE-2026-19299: IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitiv
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to path traversal.
nvd
CVE-2026-10546P3MEDIUMCVSS 6.5≥ 1.0.0, ≤ 1.9.32026-06-30
CVE-2026-10546 [MEDIUM] CWE-918 CVE-2026-10546: IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) vulnerability in
IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the URL component ( src/lfx/src/lfx/components/data_source/url.py ) due to a Time-of-Check/Time-of-Use (TOCTOU) race condition that can be exploited via DNS rebinding.
nvd
CVE-2026-17627P3HIGHCVSS 7.1≥ 1.0.0, ≤ 1.10.22026-09-04
CVE-2026-17627 [HIGH] CWE-639 CVE-2026-17627: IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitiv
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information and inject messages into workflow history due to improper authorization.
nvd
CVE-2026-93448P3MEDIUMCVSS 6.5≥ 1.0.0, ≤ 1.12.22026-10-07
CVE-2026-93448 [MEDIUM] CWE-22 CVE-2026-93448: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitiv
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
nvd
CVE-2026-101329P3MEDIUMCVSS 6.5≥ 1.0.0, ≤ 1.12.22026-10-07
CVE-2026-101329 [MEDIUM] CWE-284 CVE-2026-101329: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitiv
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper access control.
nvd
CVE-2026-97671P4MEDIUMCVSS 6.5≥ 1.0.0, ≤ 1.12.22026-10-07
CVE-2026-97671 [MEDIUM] CWE-22 CVE-2026-97671: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitiv
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to a path traversal vulnerability.
nvd
CVE-2026-17628P3MEDIUMCVSS 5.4≥ 1.0.0, ≤ 1.10.22026-09-14
CVE-2026-17628 [MEDIUM] CWE-287 CVE-2026-17628: IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to change the pass
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to change the password of an account due to improper authentication.
nvd
CVE-2026-12766P4MEDIUMCVSS 5.4≥ 1.0.0, ≤ 1.11.22026-09-14
CVE-2026-12766 [MEDIUM] CWE-918 CVE-2026-12766: IBM Langflow OSS 1.0.0 through 1.11.2 is vulnerable to server-side request forgery (SSRF). This may
IBM Langflow OSS 1.0.0 through 1.11.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
nvd
CVE-2026-79723P4MEDIUMCVSS 5.0≥ 1.0.0, ≤ 1.11.52026-09-10
CVE-2026-79723 [MEDIUM] CWE-918 CVE-2026-79723: IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to obtain sensitiv
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-controlled API endpoints.
nvd
CVE-2026-8447P4MEDIUMCVSS 6.1≥ 1.0.0, ≤ 1.11.22026-09-04
CVE-2026-8447 [MEDIUM] CWE-79 CVE-2026-8447: IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored cross-site scripting vulnerability in the
IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored cross-site scripting vulnerability in the Playground chat interface.
nvd
CVE-2026-18545P4MEDIUMCVSS 4.3≥ 1.0.0, ≤ 1.11.12026-08-28
CVE-2026-18545 [MEDIUM] CWE-918 CVE-2026-18545: IBM Langflow OSS 1.0.0 through 1.11.1 is vulnerable to server-side request forgery (SSRF). This may
IBM Langflow OSS 1.0.0 through 1.11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
nvd
CVE-2026-12763P4MEDIUMCVSS 4.2≥ 1.0.0, ≤ 1.11.52026-09-14
CVE-2026-12763 [MEDIUM] CWE-306 CVE-2026-12763: IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's
IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context due to improper cache key isolation in the MCP Tools component.
nvd