Skip to content
LangflowGHSA-5p5r-57fx-pmfr

Langflow vulnerable to remote code execution

Medium9.8CVE-2024-48061 · Published Nov 5, 2024 · updated Jul 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
langflow
PyPI
<= 1.0.18No fix yet
Details and references

langflow <=1.0.18 is vulnerable to Remote Code Execution (RCE) as any component provided the code functionality and the components run on the local machine rather than in a sandbox.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-94
Also known as
CVE-2024-48061, PYSEC-2026-1523

More Langflow advisories

All Langflow
DateAdvisory
Oct 312024langflow has vulnerability in PythonCodeTool component
CVE-2024-42835High9.8no fix yet
Sep 272024Inefficient Regular Expression Complexity in langflow
CVE-2024-9277Medium3.5no fix yet
Jun 102024Langflow remote code execution vulnerability
CVE-2024-37014High8.8fixed in 1.0.15
Jun 172025Langflow Unauth RCE
CVE-2025-3248Criticalfixed in 1.3.0
Aug 252025Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)
CVE-2025-57760High8.8fixed in 1.5.1
Dec 62025Langflow CORS misconfiguration enables Account Takeover and RCE
CVE-2025-34291Critical8.8fixed in 1.7.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.