The flaw can enable remote code execution (RCE), and because Langflow enables unauthenticated auto-login by default, attackers can reach the vulnerable endpoint without credentials.
| Vendor | Product | Versions |
|---|---|---|
| langflow | Langflow | 0.8.3, 1.8.4 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| open source | open source langflow | cert_advisory | 90% |
Added affected versions up to 1.8.4 and updated patch available to version 1.9.0.
Added a detailed description of the vulnerability enabling remote code execution and included a new tag for remote code execution.
Updated description with more technical detail, added affected versions, and specified the patch available in version 1.9.0.
Added product name 'Langflow' and confirmed CVSS score of 8.8.
Initial creation