VDB
Sign up
CRITICAL9.8

PYSEC-2025-36

Quick fix

PYSEC-2025-36 — langflow: upgrade to the fixed version with the command below.

pip install --upgrade 'langflow>=1.3.0'

Details

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/langflow
Introduced in: 0Fixed in: 1.3.0
Fixpip install --upgrade 'langflow>=1.3.0'

References