FAIL › dossier
Langflow
VENDOR· dossier confidence 40%
Langflow is an open-source AI workflow builder acquired by DataStax, but it carries a critical security risk profile with multiple high-severity vulnerabilities actively exploited by attackers, including IDOR and RCE flaws.
PROFILE
CategorySoftware VendorWhat they doLangflow is an open-source, low-code platform for building AI workflows and applications using a visual drag-and-drop interface. It is developed by Logspace, a startup acquired by DataStax in April 2024.Founded2022
Websitehttps://www.piwheels.org/project/langflow/ ↗
SECURITY POSTURE
High-risk security posture with multiple critical and high-severity vulnerabilities actively exploited by attackers, including IDOR and RCE flaws.
Notable failures
- CVE-2026-55255: Authenticated attackers can execute any user's flow via IDOR
- CVE-2026-7663: Unauthenticated access to protected MCP project resources
- CVE-2026-33017: Unauthenticated public flow creation via code injection
- CVE-2025-34291: Cross-origin credential theft via permissive CORS and cookie settings
Patterns: Repeated authorization bypasses in flow execution endpoints; Improper authentication enforcement on build and API endpoints; CISA KEV catalog inclusion due to active exploitation
FAILURE HISTORY · 23
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-05-21 | CVE-2025-34291 | high | Langflow's overly permissive CORS and SameSite=None cookie settings enable cross-origin credential theft leading to full system compromise. |
| 2026-05-21 | CVE-2025-34291 | high | Langflow's overly permissive CORS and SameSite=None cookie settings enable cross-origin credential theft leading to full system compromise. |
| 2025-05-05 | CVE-2025-3248 | critical | Langflow's missing authentication flaw lets unauthenticated attackers execute arbitrary code via its code validation endpoint. |
| 2025-05-05 | CVE-2025-3248 | critical | Langflow's missing authentication flaw lets unauthenticated attackers execute arbitrary code via its code validation endpoint. |
| 2026-08-04 | CVE-2026-9198 | high | IBM Langflow Code Injection Vulnerability allows RCE. |
| 2026-07-21 | CVE-2026-0770 | high | Langflow RCE due to untrusted code execution |
| 2026-07-21 | CVE-2026-0770 | high | Langflow RCE due to untrusted code execution |
| 2026-03-25 | CVE-2026-33017 | high | Langflow allows unauthenticated public flow creation via code injection, enabling attackers to bypass security controls. |
| 2026-03-25 | CVE-2026-33017 | high | Langflow allows unauthenticated public flow creation via code injection, enabling attackers to bypass security controls. |
| 2026-07-07 | CVE-2026-55255 | high | Langflow allows authenticated attackers to execute any user's flow by specifying a victim's flow ID, bypassing authorization controls. |
| 2026-07-07 | CVE-2026-55255 | high | Langflow allows authenticated attackers to execute any user's flow by specifying a victim's flow ID, bypassing authorization controls. |
| 2026-06-30 | CVE-2026-7663 | critical | IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint. |
| 2026-06-30 | CVE-2026-7663 | critical | IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint. |
| 2026-06-30 | CVE-2026-10560 | high | IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoints that allows an unauthenticated attacker to read build event data or cancel jobs using a valid job identifier, resulting in information disclosure and denial |
| 2026-06-30 | CVE-2026-10560 | high | IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoints that allows an unauthenticated attacker to read build event data or cancel jobs using a valid job identifier, resulting in information disclosure and denial |
| 2026-08-05 | CVE-2026-9205 | high | CVE-2026-9205: IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in t |
| 2026-08-05 | CVE-2026-8470 | high | CVE-2026-8470: IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10. |
| 2026-08-05 | CVE-2026-8470 | high | CVE-2026-8470: IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10. |
| 2026-08-05 | CVE-2026-9205 | high | CVE-2026-9205: IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in t |
| 2026-07-17 | CVE-2026-13448 | high | CVE-2026-13448: IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated re |
| 2026-07-17 | CVE-2026-13448 | high | CVE-2026-13448: IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated re |
| 2025-04-07 | CVE-2025-3248 | critical | CVE-2025-3248: Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/ |
| 2025-04-07 | CVE-2025-3248 | critical | CVE-2025-3248: Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/ |
DOSSIER SOURCES
- Credo Technology Group Holding (CRDO) Company Profile & Description · stockanalysis.com
- General Dynamics | Home · www.gd.com
- piwheels - langflow · www.piwheels.org
- DataStax acquiert la startup derrière le constructeur d'IA low-code ... · www.soutenonsnosentreprises.fr
- Langflow CVE-2026-55255 Is on CISA's Exploited List — Attackers Are ... · chatforest.com
- Langflow CVE-2026-55255: CISA warns of exploited AI workflow flaw · cyber-ivy.com
- Langflow CVE-2026-55255 Is on CISA's Exploited List — Attackers Are ... · chatforest.com
- Patch Langflow now: CISA flags CVE-2026-55255 as actively exploited · linkloot.io
- CISA Warns About Langflow Authorization Bypass Vulnerability ... · threatprotect.qualys.com
Open questions: Current patch status for CVE-2026-55255 and other KEV-listed vulnerabilities · DataStax's security governance and incident response procedures for Langflow
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-14 03:55:34.926782+00:00