Safeguard
Tag

langflow

Safeguard articles tagged "langflow" — guides, analysis, and best practices for software supply chain and application security.

8 articles

Vulnerability Analysis

CVE-2025-3248: Langflow Missing Authentication Vulnerability

CVE-2025-3248 affects Langflow Langflow and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-05-05.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2026-33017: Langflow Code Injection Vulnerability

CVE-2026-33017 affects Langflow Langflow and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-03-25.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2025-34291: Langflow Origin Validation Error Vulnerability

CVE-2025-34291 affects Langflow Langflow and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-05-21.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2026-55255: Langflow Authorization Bypass Through User-Controlled Key Vulnerability

CVE-2026-55255 affects Langflow Langflow and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-07-07.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2026-0770: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

CVE-2026-0770 affects Langflow Langflow and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-07-21.

Sep 17, 20263 min read
Vulnerability Analysis

Langflow and Marimo: When the AI Platform's Core Feature Is the Vulnerability

Three confirmed-exploited CVEs across Langflow and Marimo show what happens when a code-execution-by-design platform ships an authentication gap on the endpoint meant to guard it.

Sep 16, 20265 min read
Vulnerability Analysis

Langflow, MLflow, Ray, LiteLLM and Kestra: AI Orchestration Platforms Enter CISA's KEV Catalogue

Five AI and ML orchestration platforms had vulnerabilities confirmed as exploited in the wild between July and September 2026 — Langflow twice, then MLflow, Ray, and Kestra. Five different root causes, one shared category.

Sep 16, 20265 min read
Vulnerability Analysis

CVE-2026-9198: Two Endpoints, No Password, Full Remote Code Execution

Langflow's auto-login endpoint mints a superuser token for anyone who asks. Its code-validation endpoint runs Python through exec(). Chained, that is unauthenticated RCE at CVSS 9.8.

Aug 10, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.