Skip to main content

Langflow security briefs

3 published alerts for Langflow products and services.

Actively exploited (KEV)

CVE-2026-0770

Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

Langflow Langflow is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-0770). Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations. CISA remediation due date: 2026-07-24. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Actively exploited (KEV)

CVE-2026-55255

Langflow Authorization Bypass Through User-Controlled Key Vulnerability

Langflow Langflow is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-55255). Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. CISA remediation due date: 2026-07-10. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Actively exploited (KEV)Ransomware

CVE-2025-3248

Langflow Missing Authentication Vulnerability

Langflow Langflow is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-3248). Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted HTTP requests. CISA remediation due date: 2025-05-26. If you need help checking exposure, call (864) 335-9223.