langflow
Safeguard articles tagged "langflow" — guides, analysis, and best practices for software supply chain and application security.
8 articles
CVE-2025-3248: Langflow Missing Authentication Vulnerability
CVE-2025-3248 affects Langflow Langflow and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-05-05.
CVE-2026-33017: Langflow Code Injection Vulnerability
CVE-2026-33017 affects Langflow Langflow and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-03-25.
CVE-2025-34291: Langflow Origin Validation Error Vulnerability
CVE-2025-34291 affects Langflow Langflow and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-05-21.
CVE-2026-55255: Langflow Authorization Bypass Through User-Controlled Key Vulnerability
CVE-2026-55255 affects Langflow Langflow and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-07-07.
CVE-2026-0770: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
CVE-2026-0770 affects Langflow Langflow and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-07-21.
Langflow and Marimo: When the AI Platform's Core Feature Is the Vulnerability
Three confirmed-exploited CVEs across Langflow and Marimo show what happens when a code-execution-by-design platform ships an authentication gap on the endpoint meant to guard it.
Langflow, MLflow, Ray, LiteLLM and Kestra: AI Orchestration Platforms Enter CISA's KEV Catalogue
Five AI and ML orchestration platforms had vulnerabilities confirmed as exploited in the wild between July and September 2026 — Langflow twice, then MLflow, Ray, and Kestra. Five different root causes, one shared category.
CVE-2026-9198: Two Endpoints, No Password, Full Remote Code Execution
Langflow's auto-login endpoint mints a superuser token for anyone who asks. Its code-validation endpoint runs Python through exec(). Chained, that is unauthenticated RCE at CVSS 9.8.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.