Skip to content
LangflowGHSA-qg33-x2c5-6p44

Langflow remote code execution vulnerability

High8.8CVE-2024-37014 · Published Jun 10, 2024 · updated Jan 21, 2025

Langflow allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and provide a Python script.

GitHub advisory

Affected versions

PackageAffectedFixed in
langflow
PyPI
< 1.0.151.0.15
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-913, CWE-94
Also known as
CVE-2024-37014, PYSEC-2024-177

More Langflow advisories

All Langflow
Advisory
Langflow CORS misconfiguration enables Account Takeover and RCE
Critical8.8Dec 6, 2025
Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)
High8.8Aug 25, 2025
Langflow Unauth RCE
CriticalJun 17, 2025
Langflow vulnerable to remote code execution
Medium9.8Nov 5, 2024
langflow has vulnerability in PythonCodeTool component
High9.8Oct 31, 2024
Inefficient Regular Expression Complexity in langflow
Medium3.5Sep 27, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.