langflow security advisories
2 threat alerts tracking vulnerabilities and security advisories that affect langflow products.
Vulnios monitors langflow CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent langflow security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2026-0770 — langflow — langflow
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected ins
criticalCVE-2026-0770Critical Vulnerability: CVE-2025-3248 — langflow — langflow
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary cod
criticalCVE-2025-3248
Track langflow exposure across your environment
Vulnios automatically cross-references your asset inventory against new langflow CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan