Skip to content

DataStax security advisories

32 advisories across Langflow

Company profile
DateAdvisory
Jun 19Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
CVE-2026-55447Critical9.6fixed in 1.9.2
Jun 19Langflow: Unauthenticated DoS through multipart form boundary file upload
CVE-2026-55446High7.5fixed in 1.0.19
Jun 19Langflow: Logout button does not clear session
CVE-2026-55423Medium6.1fixed in 1.7.0
Jun 19Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
CVE-2026-55255High8.4fixed in 1.9.1
Jun 17Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
CVE-2026-55450Critical9.3fixed in 1.9.1
Jun 16Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read
CVE-2026-48520Medium6.1fixed in 1.10.0
Jun 16Langflow: Unauthenticated RCE in Shareable Playgrounds
CVE-2026-48519Critical9.6fixed in 1.9.2
Jun 16Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint
CVE-2026-42867Medium6.5fixed in 1.9.0
Jun 16Langflow: IDOR/BOLA in Monitor API , Missing Ownership Enforcement on 7 Endpoints
CVE-2026-33760High8.8fixed in 1.9.0
May 5Langflow Knowledge Bases API is Vulnerable to Path Traversal
CVE-2026-42048Critical9.6fixed in 1.9.0
Apr 20Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint
CVE-2026-6598Low4.3fixed in 1.9.1
Apr 20Langflow vulnerable to injection
CVE-2026-6599Low6.3no fix yet
Apr 20Langflow has an Information Leak through Incomplete API Key Redaction
CVE-2026-6597Low2.7no fix yet
Mar 27Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check
CVE-2026-34046Highfixed in 1.5.1
Mar 26Langflow has Authenticated Code Execution in Agentic Assistant Validation
CVE-2026-33873Criticalfixed in 1.9.0
Mar 20langflow: /profile_pictures/{folder_name}/{file_name} endpoint file reading
CVE-2026-33497Highfixed in 1.7.1
Mar 20langflow has Unauthenticated IDOR on Image Downloads
CVE-2026-33484High7.5fixed in 1.9.0
Mar 19Langflow has an Arbitrary File Write (RCE) via v2 API
CVE-2026-33309Critical9.9fixed in 1.9.0
Mar 18Langflow is Missing Ownership Verification in API Key Deletion (IDOR)
CVE-2026-33053Highfixed in 1.9.0
Mar 17Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint
CVE-2026-33017Critical9.8fixed in 1.9.0
Feb 27Langflow has Remote Code Execution in CSV Agent
CVE-2026-27966Critical9.8no fix yet
Jan 23Langflow affected by Remote Code Execution via validate_code() exec()
CVE-2026-0770Highno fix yet
Jan 2Langflow Missing Authentication on Critical API Endpoints
CVE-2026-21445Highfixed in 1.7.1
Dec 192025External Control of File Name or Path in Langflow
CVE-2025-68478High7.1fixed in 1.7.1
Dec 192025Langflow vulnerable to Server-Side Request Forgery
CVE-2025-68477High7.7fixed in 1.7.1
Dec 62025Langflow CORS misconfiguration enables Account Takeover and RCE
CVE-2025-34291Critical8.8fixed in 1.7.0
Aug 252025Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)
CVE-2025-57760High8.8fixed in 1.5.1
Jun 172025Langflow Unauth RCE
CVE-2025-3248Criticalfixed in 1.3.0
Nov 52024Langflow vulnerable to remote code execution
CVE-2024-48061Medium9.8no fix yet
Oct 312024langflow has vulnerability in PythonCodeTool component
CVE-2024-42835High9.8no fix yet
Sep 272024Inefficient Regular Expression Complexity in langflow
CVE-2024-9277Medium3.5no fix yet
Jun 102024Langflow remote code execution vulnerability
CVE-2024-37014High8.8fixed in 1.0.15
About DataStax

DataStax, Inc. is a real-time data for AI company based in Santa Clara, California. Its product Astra DB is a cloud database-as-a-service based on Apache Cassandra.

Elsewhere on fru.dev: Acquisitions · Paydays

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.