Skip to content
COOEY

FAIL › dossier

Langflow

VENDOR

· dossier confidence 40%

Langflow is an open-source AI workflow builder acquired by DataStax, but it carries a critical security risk profile with multiple high-severity vulnerabilities actively exploited by attackers, including IDOR and RCE flaws.

PROFILE
CategorySoftware VendorWhat they doLangflow is an open-source, low-code platform for building AI workflows and applications using a visual drag-and-drop interface. It is developed by Logspace, a startup acquired by DataStax in April 2024.Founded2022 Websitehttps://www.piwheels.org/project/langflow/ ↗
SECURITY POSTURE

High-risk security posture with multiple critical and high-severity vulnerabilities actively exploited by attackers, including IDOR and RCE flaws.

Notable failures
  • CVE-2026-55255: Authenticated attackers can execute any user's flow via IDOR
  • CVE-2026-7663: Unauthenticated access to protected MCP project resources
  • CVE-2026-33017: Unauthenticated public flow creation via code injection
  • CVE-2025-34291: Cross-origin credential theft via permissive CORS and cookie settings
Patterns: Repeated authorization bypasses in flow execution endpoints; Improper authentication enforcement on build and API endpoints; CISA KEV catalog inclusion due to active exploitation
FAILURE HISTORY · 23
DATEEVENTSEVSUMMARY
2026-05-21 CVE-2025-34291 high Langflow's overly permissive CORS and SameSite=None cookie settings enable cross-origin credential theft leading to full system compromise.
2026-05-21 CVE-2025-34291 high Langflow's overly permissive CORS and SameSite=None cookie settings enable cross-origin credential theft leading to full system compromise.
2025-05-05 CVE-2025-3248 critical Langflow's missing authentication flaw lets unauthenticated attackers execute arbitrary code via its code validation endpoint.
2025-05-05 CVE-2025-3248 critical Langflow's missing authentication flaw lets unauthenticated attackers execute arbitrary code via its code validation endpoint.
2026-08-04 CVE-2026-9198 high IBM Langflow Code Injection Vulnerability allows RCE.
2026-07-21 CVE-2026-0770 high Langflow RCE due to untrusted code execution
2026-07-21 CVE-2026-0770 high Langflow RCE due to untrusted code execution
2026-03-25 CVE-2026-33017 high Langflow allows unauthenticated public flow creation via code injection, enabling attackers to bypass security controls.
2026-03-25 CVE-2026-33017 high Langflow allows unauthenticated public flow creation via code injection, enabling attackers to bypass security controls.
2026-07-07 CVE-2026-55255 high Langflow allows authenticated attackers to execute any user's flow by specifying a victim's flow ID, bypassing authorization controls.
2026-07-07 CVE-2026-55255 high Langflow allows authenticated attackers to execute any user's flow by specifying a victim's flow ID, bypassing authorization controls.
2026-06-30 CVE-2026-7663 critical IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.
2026-06-30 CVE-2026-7663 critical IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.
2026-06-30 CVE-2026-10560 high IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoints that allows an unauthenticated attacker to read build event data or cancel jobs using a valid job identifier, resulting in information disclosure and denial
2026-06-30 CVE-2026-10560 high IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoints that allows an unauthenticated attacker to read build event data or cancel jobs using a valid job identifier, resulting in information disclosure and denial
2026-08-05 CVE-2026-9205 high CVE-2026-9205: IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in t
2026-08-05 CVE-2026-8470 high CVE-2026-8470: IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.
2026-08-05 CVE-2026-8470 high CVE-2026-8470: IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.
2026-08-05 CVE-2026-9205 high CVE-2026-9205: IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in t
2026-07-17 CVE-2026-13448 high CVE-2026-13448: IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated re
2026-07-17 CVE-2026-13448 high CVE-2026-13448: IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated re
2025-04-07 CVE-2025-3248 critical CVE-2025-3248: Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/
2025-04-07 CVE-2025-3248 critical CVE-2025-3248: Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/
Open questions: Current patch status for CVE-2026-55255 and other KEV-listed vulnerabilities · DataStax's security governance and incident response procedures for Langflow
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-14 03:55:34.926782+00:00