|
51
|
9.8 |
CRITICAL
Network
|
langflow
|
langflow
|
IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the public flow build endpoint ( /api/v1/build_public_tmp/{flow_id}/flow ). The vu…
New
|
NVD-CWE-noinfo
|
CVE-2026-13448
|
2026-07-21 03:16 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
52
|
8.8 |
HIGH
Network
|
langflow
|
langflow
|
IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input…
New
|
CWE-78
OS Command
|
CVE-2026-14499
|
2026-07-21 03:12 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
53
|
8.8 |
HIGH
Network
|
langflow
|
langflow
|
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacker-controlled URL that returns a specially crafted Content-Disposition header (e…
New
|
CWE-22
Path Traversal
|
CVE-2026-7667
|
2026-07-21 03:10 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
54
|
6.5 |
MEDIUM
Network
|
langflow
|
langflow
|
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure default configuration and incomplete enforcement of the SSRF protection mechanism.
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-7754
|
2026-07-21 03:03 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
55
|
8.8 |
HIGH
Network
|
langflow
|
langflow
|
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcement on MCP server configuration files.
New
|
NVD-CWE-noinfo
|
CVE-2026-7755
|
2026-07-21 03:01 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
56
|
9.9 |
CRITICAL
Network
|
langflow
|
langflow
|
IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts user-supplied Python …
New
|
CWE-94
Code Injection
|
CVE-2026-8481
|
2026-07-21 03:00 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
57
|
8.1 |
HIGH
Network
|
langflow
|
langflow
|
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication tokens for any user.
New
|
CWE-22
Path Traversal
|
CVE-2026-7872
|
2026-07-21 02:59 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
58
|
8.8 |
HIGH
Network
|
langflow
|
langflow
|
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API. A critical security flaw exists in the parameter filtering mechanism within t…
New
|
CWE-94
Code Injection
|
CVE-2026-8056
|
2026-07-21 02:57 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
59
|
9.8 |
CRITICAL
Network
|
langflow
|
langflow
|
IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses…
New
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-8505
|
2026-07-21 02:56 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
60
|
9.9 |
CRITICAL
Network
|
langflow
|
langflow
|
IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's unsafe pickle.loads() function…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-8476
|
2026-07-21 02:56 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|