Search Results (23 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-48061 1 Langflow 1 Langflow 2025-05-28 9.8 Critical
langflow <=1.0.18 is vulnerable to Remote Code Execution (RCE) as any component provided the code functionality and the components run on the local machine rather than in a sandbox.
CVE-2024-42835 1 Langflow 1 Langflow 2025-05-27 9.8 Critical
langflow v1.0.12 was discovered to contain a remote code execution (RCE) vulnerability via the PythonCodeTool component.
CVE-2024-37014 1 Langflow 1 Langflow 2024-11-21 8.8 High
Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and provide a Python script.