Skip to content
Threat Feed

Vendor

Langflow

9 briefs RSS
high advisory

Multiple Vulnerabilities in Langflow

Langflow is affected by multiple vulnerabilities that allow an unauthenticated attacker to achieve remote code execution and bypass security controls.

Langflow vulnerability remote-code-execution security-bypass
1t
high advisory

Remote Code Execution Vulnerability in Langflow

A vulnerability in Langflow allows a remote, authenticated attacker to execute arbitrary code, necessitating strict monitoring of service-level process execution and authentication logs.

Langflow vulnerability rce authentication
2t
critical threat

DD-WRT Stack-Based Buffer Overflow Vulnerability (CVE-2021-27137)

CVE-2021-27137 is a stack-based buffer overflow vulnerability in DD-WRT's UPnP component that allows an unauthenticated attacker to trigger remote code execution on affected router devices.

exploited DD-WRT +2 vulnerability-exploitation firmware router rce buffer-overflow
1t 4c
critical threat

CVE-2026-63030: Critical Remote Code Execution Vulnerability in WordPress Core

CVE-2026-63030 is a critical unauthenticated remote code execution vulnerability affecting WordPress Core versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1, allowing an unauthenticated attacker to execute arbitrary code via the WordPress REST API batch endpoint, potentially leading to complete website compromise.

exploited PoC WordPress Core 6.9.0 +51 wordpress rce web-vulnerability cve
2t 15c 8i updated
high threat

Agentic AI Used to Conduct Ransomware Attack via Langflow

Threat actor JadePuffer exploited CVE-2025-3248 in Langflow instances, leveraging agentic LLM capabilities for advanced reconnaissance, lateral movement, and ultimately encrypting data on production servers with ransomware.

exploited Langflow +1 JadePuffer ransomware ai agentic-ai vulnerability-exploitation data-encryption lateral-movement persistence
2r 10t 2c
critical advisory

Langflow 1.3.0 Remote Code Execution Vulnerability

Langflow 1.3.0 contains a remote code execution vulnerability (CVE-2026-0770) due to untrusted input in the exec_globals parameter at the validate endpoint, allowing remote attackers to execute arbitrary code as root without authentication, as demonstrated by a public exploit.

langflow 1.3.0 +3 remote-code-execution webapps langflow
1r 1t 5i updated
critical threat

Citrix NetScaler ADC and Gateway CVE-2026-3055 Exploitation

Threat actors are actively exploiting CVE-2026-3055, a critical memory overread vulnerability in Citrix NetScaler ADC and NetScaler Gateway appliances configured as a SAML identity provider (IDP), to extract sensitive information, including authenticated administrative session IDs, potentially leading to full system takeover.

PoC Langflow +4 citrix netscaler cve-2026-3055 memory-overread information-disclosure
2r 3t 5c 1i updated
critical threat

Critical RCE Vulnerability in Langflow AI Pipelines (CVE-2026-33017)

A critical remote code execution vulnerability, CVE-2026-33017, exists in Langflow AI pipelines prior to version 1.9.0 that allows an unauthenticated remote attacker to execute code with full server process privileges, impacting availability, integrity, and confidentiality.

Siyuan +6 langflow rce cve-2026-33017 ai-pipeline
2r 2t 1i updated
medium advisory

Langflow Unauthenticated Image Retrieval Vulnerability (CVE-2026-33484)

Langflow versions 1.0.0 through 1.8.1 are vulnerable to an unauthenticated image retrieval vulnerability (CVE-2026-33484) that allows attackers to download any user's uploaded images without credentials in multi-tenant deployments by accessing the `/api/v1/files/images/{flow_id}/{file_name}` endpoint.

Langflow unauthenticated-access image-retrieval vulnerability
2r 1t