A security update addressing several vulnerabilities has been released for Langflow OSS.
Affected Versions are Langflow OSS 1.0.0 Through 1.10.3.
The identified vulnerabilities include CVE-2026-8182, CVE-2026-8183, CVE-2026-8470, CVE-2026-8478, CVE-2026-9081, CVE-2026-9130, CVE-2026-9196, CVE-2026-9201, CVE-2026-9205, CVE-2026-10128, CVE-2026-17624, CVE-2026-17629, CVE-2026-17632, and CVE-2026-17633.
Key issues include unauthenticated remote code execution, path traversal, prediction of the encryption key due to the use of non-cryptographic random number generators, arbitrary code execution due to insufficient control over user-input code, server-side request forgery (SSRF) (a vulnerability that causes the server to send requests on the user’s behalf), Bypassing authorization in MemoryComponent, unintended code execution due to inadequate handling of LLM-generated components during the Agentic Assistant validation process, arbitrary code execution due to cryptographic vulnerabilities in the custom component validation process, vulnerable encryption key derivation, exposure of server environment variables in built-in components, arbitrary code execution due to insufficient validation of module imports, SQL injection, arbitrary code execution due to insufficient validation of Python code during the AST-based security checking process, and arbitrary code execution due to code injection.
Patches have been provided via the latest update, and it is recommended to update to Langflow OSS version 1.11.0 Or higher, which is the latest version of the Vulnerability Patch.