LangflowGHSA-qg33-x2c5-6p44
Langflow remote code execution vulnerability
High8.8CVE-2024-37014 · Published Jun 10, 2024 · updated Jan 21, 2025
Langflow allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and provide a Python script.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| langflow PyPI | < 1.0.15 | 1.0.15 |
Details and references
More Langflow advisories
All Langflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Dec 62025 | Langflow CORS misconfiguration enables Account Takeover and RCE | Critical8.8 | 1.7.0 |
| Aug 252025 | Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE) | High8.8 | 1.5.1 |
| Jun 172025 | Langflow Unauth RCE | Critical | 1.3.0 |
| Nov 52024 | Langflow vulnerable to remote code execution | Medium9.8 | No fix yet |
| Oct 312024 | langflow has vulnerability in PythonCodeTool component | High9.8 | No fix yet |
| Sep 272024 | Inefficient Regular Expression Complexity in langflow | Medium3.5 | No fix yet |