LangflowGHSA-56m6-4mhw-h3g5
langflow has vulnerability in PythonCodeTool component
High9.8CVE-2024-42835 · Published Oct 31, 2024 · updated Jun 6, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| langflow PyPI | <= 1.0.12 | No fix yet |
Details and references
langflow v1.0.12 was discovered to contain a remote code execution (RCE) vulnerability via the PythonCodeTool component.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Also known as
- CVE-2024-42835, PYSEC-2024-279
More Langflow advisories
All Langflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Nov 52024 | Langflow vulnerable to remote code execution CVE-2024-48061Medium9.8no fix yet | Medium9.8 | No fix yet |
| Sep 272024 | Inefficient Regular Expression Complexity in langflow CVE-2024-9277Medium3.5no fix yet | Medium3.5 | No fix yet |
| Jun 102024 | Langflow remote code execution vulnerability CVE-2024-37014High8.8fixed in 1.0.15 | High8.8 | 1.0.15 |
| Jun 172025 | Langflow Unauth RCE CVE-2025-3248Criticalfixed in 1.3.0 | Critical | 1.3.0 |
| Aug 252025 | Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE) CVE-2025-57760High8.8fixed in 1.5.1 | High8.8 | 1.5.1 |
| Dec 62025 | Langflow CORS misconfiguration enables Account Takeover and RCE CVE-2025-34291Critical8.8fixed in 1.7.0 | Critical8.8 | 1.7.0 |