Langflow Product Security Update Advisory (CVE-2026-0770)
Overview Inappropriate handling of the exec_globals parameter in Langflow’s validate endpoint could lead to remote code execution (a vulnerability that allows a threat actor to execute arbitrary code remotely). Affected Systems Langflow version 1.7.3 Or earlier. The vulnerability identifier is CVE-2026-0770. Impact Remote code execution is possible. The CVSSv3 score
Langflow Product Security Update Advisory (CVE-2026-55255)
Overview A security update has been released to address a vulnerability in the Langflow product. This vulnerability is identified as CVE-2026-55255. Affected Versions Langflow versions prior to 1.9.1. Vulnerability Details An insecure direct object reference (IDOR) vulnerability—where an authenticated user can access objects they are not authorized to access—was identified
IBM Product Security Update Advisory
A security update has been released to address a vulnerability in an IBM product. the affected product is IBM Langflow Desktop, and versions 1.0.0 through 1.8.4 are affected. CVE-2026-4503 is an unauthenticated Insecure Direct Object Reference (IDOR) vulnerability that occurs in the Langflow Desktop image download endpoint. CVE-2026-6543 is a
Langflow Product Security Update Advisory (CVE-2026-33017)
overview We have released a security update that addresses a vulnerability in Langflow products. users of affected products are encouraged to update to the latest version. affected products CVE-2026-33017 Langflow version: 1.8.1 and earlier resolved Vulnerabilities Remote code execution vulnerability on the endpoint (CVE-2026-33017) vulnerability patches Vulnerability patches have been
Langflow Product Security Update Advisory (CVE-2025-3248)
Overview We have released a security update to fix vulnerabilities in Langflow products. Users of affected products are advised to update to the latest version. Affected Products CVE-2025-3248 Langflow Version: 1.3.0 and earlier Resolved Vulnerabilities Arbitrary code execution vulnerability on the endpoint (CVE-2025-3248)

