VDB
KO
CRITICAL 9.8

GHSA-5p5r-57fx-pmfr

Langflow vulnerable to remote code execution

Details

langflow <=1.0.18 is vulnerable to Remote Code Execution (RCE) as any component provided the code functionality and the components run on the local machine rather than in a sandbox.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / langflow
Introduced in: 0

No fixed version published yet for langflow (pip). Pin to a known-safe version or switch to an alternative.

References