GHSA-5p5r-57fx-pmfr
GitHub Security Advisory
Langflow vulnerable to remote code execution
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
langflow <=1.0.18 is vulnerable to Remote Code Execution (RCE) as any component provided the code functionality and the components run on the local machine rather than in a sandbox.
Affected Packages
PyPI
langflow
Affected versions:
0
(last affected: 1.0.18)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: June 16, 2025 6:25 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.