By vendor
Langflow vulnerabilities
Known CVEs affecting Langflow products, prioritized by severity, with SEC.co remediation and detection guidance.
1 published vulnerability
- CVE-2026-3341MEDIUM 5.4
IBM Langflow Desktop versions 1.0.0 through 1.9.2 contain a server-side request forgery (SSRF) vulnerability that allows authenticated users to make unauthorized network requests from the affected system. An attacker with valid credentials could exploit this to map internal networks, access restricted services, or set up for secondary attacks. The vulnerability requires authentication, which reduces—but does not eliminate—the risk in environments where account compromise is possible.