LangflowGHSA-5p5r-57fx-pmfr
Langflow vulnerable to remote code execution
Medium9.8CVE-2024-48061 · Published Nov 5, 2024 · updated Jul 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| langflow PyPI | <= 1.0.18 | No fix yet |
Details and references
langflow <=1.0.18 is vulnerable to Remote Code Execution (RCE) as any component provided the code functionality and the components run on the local machine rather than in a sandbox.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-94
- Also known as
- CVE-2024-48061, PYSEC-2026-1523
- nvd.nist.gov/vuln/detail/CVE-2024-48061
- github.com/langflow-ai/langflow/issues/696
- gist.github.com/AfterSnows/1e58257867002462923fd62dde2b5d61
- github.com/langflow-ai/langflow
- rumbling-slice-eb0.notion.site/There-is-a-Remote-Code-Execution-RCE-vulnerability-in-the-repository-https-github-com-langflow-a-105e3cda9e8c800fac92f1b571bd40d8
More Langflow advisories
All Langflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 312024 | langflow has vulnerability in PythonCodeTool component CVE-2024-42835High9.8no fix yet | High9.8 | No fix yet |
| Sep 272024 | Inefficient Regular Expression Complexity in langflow CVE-2024-9277Medium3.5no fix yet | Medium3.5 | No fix yet |
| Jun 102024 | Langflow remote code execution vulnerability CVE-2024-37014High8.8fixed in 1.0.15 | High8.8 | 1.0.15 |
| Jun 172025 | Langflow Unauth RCE CVE-2025-3248Criticalfixed in 1.3.0 | Critical | 1.3.0 |
| Aug 252025 | Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE) CVE-2025-57760High8.8fixed in 1.5.1 | High8.8 | 1.5.1 |
| Dec 62025 | Langflow CORS misconfiguration enables Account Takeover and RCE CVE-2025-34291Critical8.8fixed in 1.7.0 | Critical8.8 | 1.7.0 |