VendorsLangflowlangflow_desktopany version
Vulnerabilities

Langflow Langflow Desktop any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2026-6543
Authenticated Remote Code Execution Vulnerability in Langflow Code Validation Endpoint
Published 2026-04-30 · Analyzed
8.8EPSS 0.007
CVE-2026-4503
Unauthenticated Insecure Direct Object Reference (IDOR) Vulnerability in Langflow Desktop Image Download Endpoint
Published 2026-04-30 · Analyzed
7.5EPSS 0.004
CVE-2026-3345
Path Traversal and Arbitrary File Write Vulnerability in IBM Langflow Desktop API v2 File Upload Endpoint
Published 2026-04-30 · Analyzed
6.5EPSS 0.006
CVE-2026-4502
Arbitrary File Write and Remote Code Execution Vulnerability in Langflow v2 API
Published 2026-04-30 · Analyzed
6.5EPSS 0.004
CVE-2026-3340
Server-Side Request Forgery (SSRF) in Langflow URL Component
Published 2026-04-30 · Analyzed
6.5EPSS 0.003
CVE-2026-3346
Stored Cross-Site Scripting (XSS) in Langflow Markdown Rendering via rehypeRaw
Published 2026-04-30 · Analyzed
6.4EPSS 0.003
CVE-2026-3341
IBM Langflow Desktop 1.0.0 - 1.9.2 DNS Rebinding Bypasses SSRF Protection Allowing Access to Internal Services
Published 2026-06-11 · Analyzed
5.4EPSS 0.002